Lol npm the cli has a vulnerability in a transitive dependency via a dependency which is now archived because npm the company laid off the employee who ran it for trying to unionize, so now it's not possible to run npm (or anything that depends on it) without specifically installing software with a known vulnerability.


The best bit is that I knew this at least six months ago as evidenced by

