logoalt Hacker News

rpdillonyesterday at 5:39 PM1 replyview on HN

The dependencies weren't vendored, meaning their behavior can change at any time if a malicious actor gains control of that third-party repo.

This is bad for security.


Replies

trimethylpurineyesterday at 10:31 PM

Yes, I agree. And it's sadly, as we can see, still fairly standard practice to ignore it.