Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Maintaining all that, they're bound to f-up at some point and expose vulnerabilities.

Who maintains the 1600 dependencies of a project? Pretty sure some of those expose vulnerabilities. Not counting those that are downright malware.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: