Transitive CVE Clearance: The Dual-Layer Pattern
You bump a direct dependency to pull in a patched transitive. bun audit goes green. The lockfile is committed. Two weeks later, someone does a clean install on a fresh machine, and the vulnerable tran
jeremylongshore.hashnode.dev6 min read