Hacker News new | ask | show | jobs
by F117-DK 2637 days ago
This is scary. Gems don't have any audits?
2 comments

Not this kind of audits. Is there any major language for which all third party modules are audited for security before they are released? I would be surprised.
gems don't, NPM doesn't, PyPI doesn't, NuGet doesn't.... you get the picture.

Basically all apps using package repo's (i.e. all of them) are relying on massive piles of unaudited 3rd party code with usually no idea of provenance.