logoalt Hacker News

traceroute66today at 5:29 PM0 repliesview on HN

> Most people can't justify the time commitment needed to read and then modify the code for tools they use very often.

A lot of modern open source software is often written in dependency heavy languages.

So to do a "proper" examination, by definition you need to consider the dependencies as well as the core code itself. We all know how supply-chain attacks are on the rise.