Hacker News new | ask | show | jobs
by anonym29 1295 days ago
>Being part of 'the West', would you accept the risk, evaluate the project, and eventually rely on it as a key component of your app or dismiss it immediately?

Wrong order.

I evaluate the project before accepting the risk. You need to evaluate the project in order to analyze the risks, and you need to have analyzed the risks in order to make a responsible decision on accepting them. With an in-depth code review, it shouldn't be to difficult to discover whether anything nefarious is afoot. As long as there isn't, I'd feel comfortable including that version, albeit without any kind of auto-updating (I'd want to review code changes before running the updated code).