logoalt Hacker News

fg137today at 1:10 AM1 replyview on HN

> Do you scrutinize the rest of your dependencies this way?

You don't?


Replies

Greedtoday at 5:11 AM

Enough to make judgement calls on them based on the individual Twitter posts of each of their developers? Absolutely not!

If I go beyond the initial vetting, that's a minimum of 30+ projects multiplied by however many contributors each. Without even mentioning all of their sub dependencies. It's a pipe dream to think you can ever have a complete picture of the motivations and political machinations of your entire dependency tree.

show 2 replies