Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Every dependency can run code on every computer your project runs on. That means you have to trust its author to:

1. not be malicious

2. not write a vulnerability by accident

3. not get their computer infected, their email account hijacked, etc.

4. be wise in transferring ownership

5. not add a dependency with a license incompatible with your project

All the above concerns apply recursively to the dependencies of the dependency.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: