-
npm audit is a great tool but there’s a huge problem with frontend-only projects. “If the attacker already has access to your machine and can change your configuration files, you have a much bigger problem than slow regular expressions!” overreacted.io/npm-audit-broken-by-design/