logoalt Hacker News

runningmikeyesterday at 10:50 PM4 repliesview on HN

Popularity is never a metric for security or quality….Always verify.


Replies

criddellyesterday at 10:57 PM

Verify? Verify what?

user34283yesterday at 11:00 PM

Verify what? I certainly don't have the capacity to thoroughly review my every dependency's source code in order to detect potentially hidden malware.

In this case more realistic advice would probably be to either rely on a more popular package to benefit from swarm intelligence, or creating your own implementation.

show 1 reply
k8sToGoyesterday at 10:54 PM

But... GitHub stars!

sneakyesterday at 11:07 PM

Over a certain popularity it is. 56k downloads is nowhere near the threshold.