@w666 -- there are CodeQL (and Dependabot) features available for open source project. Please see if you agree to enable CodeQL to report issues internally about the source code itself. I enabled it in my fork, and there are 13 reports in Code scanning sections. Some seem superfluous but some appear legit, like prototype pollution in some util functions. Please consider enabling it and have a look.
@w666 -- there are CodeQL (and Dependabot) features available for open source project. Please see if you agree to enable CodeQL to report issues internally about the source code itself. I enabled it in my fork, and there are 13 reports in Code scanning sections. Some seem superfluous but some appear legit, like prototype pollution in some util functions. Please consider enabling it and have a look.