The pnpm Override That Silently Defeated a Security Bump
I bumped nodemailer two majors to clear a file-read/SSRF advisory, ran install, and the old version stayed put. Two pnpm resolution traps later, the audit was finally at zero — and my CI had been testing a version my users never get.
Read more →