Open
Description
npm was recently attacked by passing in octal numbers to their IVP4 spec, which could reroute local connections to exterior connections and vice versa.
This is known is security terms as "bad".
This issue is started as a way of keeping track of potential concerns in Julia and the package ecosystem.