Somehow it is missing the "read the code of your dependency" step … :)
Even occasionally having a glance (e.g. when reading the docs) might be super helpful in discovering strange things going on.
Even occasionally having a glance (e.g. when reading the docs) might be super helpful in discovering strange things going on.
It doesn't index all of npm, only if the package was reference by a Linux distribution somehow (e.g. package-lock.json in a tar file used in an Arch Linux PKGBUILD).