One thing that is missing from https://overreacted.io/npm-audit-broken-by-design/ is a link to a proper bug report. I see https://github.com/npm/cli/issues/3930 that was closed (!!!) because it was being discussed at https://github.com/npm/rfcs/pull/422 Like THAT would even partially solve ongoing severe bug. Maybe also mention that they close bug reports under pretext that it is discussed somewhere?