> 68 vulnerabilities (21 moderate, 45 high, 2 critical)
Even installing the latest npm itself (`npm install -g npm@8.1.1`) results in
> 3 moderate severity vulnerabilities
npm itself having vulnerabilities is a more serious problem and it's not clear that they're taking it seriously.
It's a public repository of stuff. End of story. Why should NPM do the job of vetting everything? They aren't getting paid for it (or most of it).
> Headquartered in California, [GitHub] has been a subsidiary of Microsoft since 2018.
https://en.wikipedia.org/wiki/GitHub
I think they're effectively a department that generates a lot of PR. They have paid security staff.
https://jobspresso.co/job/software-engineer-platform-2-2-2-2...
This is a job posting for a security engineer at npm from July 4, that appears filled to me. I'm sure as an organization npm inc. is aware of vulnerabilities in their core product, so there's internal back and forth - the usual stuff.