Skip to content

Is create-react-app abandoned? #11086

Answered by gaearon
thomastvedt asked this question in General
Jun 10, 2021 · 9 comments · 24 replies
Discussion options

You must be logged in to vote

I want to address this part:

And after setting up a new project I get this:

101 vulnerabilties

There is no actual issue here. See #11174 for details. Basically, the way vulnerabilties are reported on npm is horribly broken because it doesn't take context into account. If you check each vulnerability report that gets flagged, you'll find that 99.9% or more are false positives because they don't apply in the context of the build tooling.

Replies: 9 comments 24 replies

Comment options

You must be logged in to vote
7 replies
@ultrox
Comment options

@ryota-murakami
Comment options

@arogozine
Comment options

@bugzpodder
Comment options

@gaearon
Comment options

Comment options

You must be logged in to vote
2 replies
@arogozine
Comment options

@ryota-murakami
Comment options

Comment options

You must be logged in to vote
4 replies
@ivanjeremic
Comment options

@ultrox
Comment options

@ivanjeremic
Comment options

@martinnormark
Comment options

Comment options

You must be logged in to vote
3 replies
@thomastvedt
Comment options

@ryota-murakami
Comment options

@arogozine
Comment options

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
6 replies
@bugzpodder
Comment options

@mrmckeb
Comment options

@gaearon
Comment options

@arogozine
Comment options

@gaearon
Comment options

Comment options

You must be logged in to vote
2 replies
@gaearon
Comment options

@thomastvedt
Comment options

Answer selected by thomastvedt
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet