pull down to refresh

Been using socket.dev for automated checks on supply chain more generally
Also my cursor rules prohibit new libs, even though they're rarely malicious they're often unnecessary or even retarded