Intresting. How different is this from regular npm security errors?
More than blocking pipelines, This plugin doesn't throw errors for an entire package if only certain methods are vulnerable. For example, in `lodash` only 3 methods are vulnerable. So, it would be wrong to flag the entire package as vulnerable, instead only throw errors if the vulnerable methods are imported/used.
That's why my ESLint plugin comes into picture and feels much better than many other tools available