Toot

Written by René Dudfield on 2024-12-11 at 06:31

[#]Golang has this concept of vulnerabilities where if your code doesn’t use the vulnerable code in the package it won’t mark your project as being vulnerable to it. The #javascript and #typescript ecosystems desperately need this. I know there are more challenges in JS world to doing this in practice though. But the amount of false positives makes vulnerability reporting for #typescript and #javascript useless to many.

=> More informations about this toot | View the thread | More toots from renedudfield@fosstodon.org

Mentions

Tags

=> View golang tag | View javascript tag | View typescript tag

Proxy Information
Original URL
gemini://mastogem.picasoft.net/toot/113632783328472862
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
218.136918 milliseconds
Gemini-to-HTML Time
0.358333 milliseconds

This content has been proxied by September (3851b).