| ▲ | cpuguy83 4 hours ago | |
In an ideal universe yes. But we live in a world where vulnerability scanners reign supreme. | ||
| ▲ | jamesfinlayson 3 hours ago | parent [-] | |
Yep, I've updated dependencies with an RCE that can't be exploited in my codebase just to keep my security team happy. Not worth the multiple arguments about it not actually being an issue. | ||