Hacker News new | ask | show | jobs
by peterhunt 1559 days ago
No one is going to audit the entire transitive closure of their dependency graph for every project they try out on their computer. This is not just going to affect the sloppy.