logoalt Hacker News

15155yesterday at 3:31 PM0 repliesview on HN

Downloading a dependency also requires a high degree of trust in whatever transitive dependencies that a trusted dependency decides to pull in.