Closed
Description
The Node.js Ecosystem Security Database is no more maintained (it's deprecated). So there is no reason to use it anymore for a production application. We should tag as deprecated in README (and also in the strategy markdown page).
- Throw a deprecation warning when we use this strategy (see process.emitWarning)
vulnera/src/strategies/index.js
Lines 15 to 16 in 51bb814
Here a link to an official Node.js article that explain why: https://nodejs.medium.com/node-js-ecosystem-vulnerability-reporting-program-winding-down-591d9a8cd2c7