Review a change for injection, authz gaps, secret handling and unsafe deserialisation, with the threat model stated rather than assumed.
Review a change for injection, authz gaps, secret handling and unsafe deserialisation, with the threat model stated rather than assumed.
This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.