Hacker News new | ask | show | jobs
by infogulch 1494 days ago
Are dependencies that run on your development machine any less of a maintenance or security concern?
2 comments

No, but the number being quoted is the sum of two different security concerns - and it’s attributing the concern to ‘react apps’, when actually react itself is pretty clean in terms of dependencies.
Yes, because they aren't running in prod.