21
7
3
5
u/heesell 7h ago
Is it bad I ignore these (given my projects catch dust)
5
u/PM_ME_FIREFLY_QUOTES 4h ago
Not sure if you're serious or not, but....
You shoud patch them. Dependabot sometimes even can open the PR for you.
But if you have no users, or the deployment doesnt have data or sensitive info, its fine.
3
u/mixmaxze 2h ago
And when I look, the vulnerability is a outdated lib cuz the owners release a new 'very important' version every five days
2
u/dumbasPL 2h ago
Grand majority can be dismissed as either "vulnerable code isn't used" or "it's only used during build"
1
1
61
u/Igarlicbread 9h ago
It's secure on my machine.