From maintaining dozens of projects over decades: yes and no.
Your custom library probably won't fall to a library-specific attack unless you were actively aiming for interoperability. However your custom library almost certainly has many vulnerabilities that you haven't heard of yet. Just a few weeks ago I saw a custom library (PHP) with SQL injection vulnerabilities, I couldn't believe it. I suggested to the client that if he still resists having another professional audit it, at least let some frontier LLM have a look. Yes, I recommended this guy to vibe code his security-sensitive code because "professional developers" today still miss the basics.
They're referring to supply chain attacks. Taking over open source libraries through social engineering and adding hidden malicious code. Becoming increasingly common.
If I could have a dollar for every casual strcpy in my DIY libraries I would be a rich man. And would never dare to put them in the line of fire of unwashed Internet :-)
I was more concerned about supply chain attacks, along with the idea of stripping down all dependencies to truly just what you need.
Need a few math operations? pull those in, instead of an entire math lib, for example.
> I suggested to the client that if he still resists having another professional audit it, at least let some frontier LLM have a look. Yes, I recommended this guy to vibe code his security-sensitive code because "professional developers" today still miss the basics.
Amen. Nowadays it is borderline malpractice to not use a coding agent for checking the security of your code.