-
Notifications
You must be signed in to change notification settings - Fork 390
Closed
Description
Hi, feel free to close this if I'm mistaken and there's actually no problem, but I just want to ask why pdf2json suddenly needed to depend on the user package?
Line 72 in da9e5d3
| "user": "^0.0.0" |
It was added in b03348e right before the release of Stable build: V3.2.1. The release notes actually claim:
keeping zero dependency
which is false.
The user package hasn't been updated in 12 years and doesn't really seem to do anything either:
It's kind of suspicious that a package like this is suddenly depended on. Actually, I can't believe that a package like this has any dependents at all, let alone 2807. Just can't help but be a bit paranoid with all the npm exploits being reported these days.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels