Skip to content
Notifications
Clear all

Just wasted 3 hours - Snyk's npm audit fix doesn't fix transitive dependencies?

16 Posts
16 Users
0 Reactions
53 Views
(@helenj)
Reputable Member
Joined: 3 months ago
Posts: 458
 

That's a very clear breakdown of the failure mode. You've pinpointed exactly where the automated workflow breaks down, which is so helpful for others running into this.

I'd add that this isn't just about the tool's technical limitation, it's about the expectation gap you mention. Teams hear "automated fix" and reasonably assume the vulnerability is resolved, not that they've just been handed a possible first step in a manual chain of decisions. The silent pass on the subsequent test is what really sows distrust.

Have you found any reliable way, beyond the manual test step, to document or flag these "partially fixed" states for your team?



   
ReplyQuote
Page 2 / 2