|
|
|
|
|
by dubcanada
2400 days ago
|
|
Well the obvious way is to look through every line of code. The package uses functions from multiple packages, if they were to instead write them all themselves you may end up with 50,000 lines of code. It's basically just split up amongst a bunch of different folders and files with a bunch of extra "garbage" and 99% unused code. So if you don't trust it, read it all. But at some point you got to trust something. |
|
Sure, you can do locking, but that does not go deep well, and also turns into a hell of trying to determine if every (for your use-case) pointless release of a sub-dep is worth updating to.