I have seen small utility libraries like tj-actions get compromised because there aren't any security specialists looking at the library.
My main concern is supply chain compromise.
My main concern is supply chain compromise.
That said, everything in my previous post still applies: a nonzero buglist is totally normal and widely accepted.