I scanned 8 popular open-source repos for outdated dependencies and CVEs. Here's what I found.
Most developers know their dependencies are probably outdated. Few know by how much.
I built ScanReq, a VS Code extension that scans dependency files, checks versions against public registries in real
trustdev.hashnode.dev6 min read