Hacker News new | past | comments | ask | show | jobs | submit
If the solution was to remove an unused dependency, I think this CVE isn't silly at all.