Earlier quoted context omitted.
I'm getting CVE fatigue with all of these super ultra critical 10/10 vulnerabilities that are some node package that compiles my frontend can get stuck if I give it a malicious regex. It's hard to spot the stuff that actually matters.
Seriously. We got 116 github dependabot alerts this week. Half of them for dev dependencies.
Ok. Hacking me by changing the input to my Jekyll rather involves being on the other side of the airtight hatch.