Yep, all the above, and more :-)
The "more" part and to be practical - there are good definitions in place on how to avoid prototype pollution vulnerabilities. There's a good lesson on the Snyk website with recommended action to mitigate that security issue:
The "more" part and to be practical - there are good definitions in place on how to avoid prototype pollution vulnerabilities. There's a good lesson on the Snyk website with recommended action to mitigate that security issue: