|
|
|
|
|
by Y7ZCQtNo39
2763 days ago
|
|
It's impractical, on an individual level, to vet your entire dependency tree. Installing something like react alone will put 100+ modules in your dependency tree. A more mature project will have a 4-figure number of dependencies. Things like Node Security Platform (which was absorbed by NPM) exist for a reason. There's no reason for every person to vet every single package they use -- it'd be an awful lot of duplicated energy. If there was no implicit trust in the community, and we had to act as vigilant as you describe, there would be no community. |
|