Hacker News new | ask | show | jobs
by mowse_winded 1074 days ago
But then did you check every one of their dependencies?
1 comments

We treated transitive dependencies the same as any other dependencies (i.e. they had to have an owner and be audited etc.). We didn't audit our suppliers' build toolchains or vendored dependencies, but would've considered them responsible if something malicious came in that way.