Hacker News new | ask | show | jobs
by cube00 1575 days ago
For a lone dev, it's impossible but I wonder if the big players like Facebook and Google actually audit all the transitive dependencies they've selected each time they release a new version of React or Angular.