logoalt Hacker News

rpdillontoday at 5:39 PM0 repliesview on HN

The dependencies weren't vendored, meaning their behavior can change at any time if a malicious actor gains control of that third-party repo.

This is bad for security.