top | item 46538286

(no title)

dimitrisnl | 1 month ago

I hate it with passion. It won't respect pinned versions in package.json. I have to explicitly exclude stuff. Be better.

discuss

order

worksonmine|1 month ago

Could you elaborate a little? Are you saying it should ignore vulnerable packages simply because you pinned it to a specific version? Or does it warn even if your specific version isn't vulnerable?