Hacker News new | ask | show | jobs
by frant-hartm 996 days ago
This is definitely true. The more complex the library is, the more chance for a vulnerability to happen. And combining 2 independent low level vulnerabilities may end up being a critical vulnerability.

The same may happen in your project, but if you use simple(r) dependencies, it's less likely.