|
|
|
|
|
by oefrha
844 days ago
|
|
That's a lot better than some frontend library adding an "Easter egg" so that every website using it, including some very serious ones, had Santa beards on their buttons on Christmas a few years back (can't find the story now). Of course you may argue it was users' fault who should have vetted every single line of their dependency, but let's be real. Unfortunately there are a lot of unprofessional people in open source, and while I hate to stereotype, they are especially prevalent in the JavaScript community where it's typical to have hundreds to thousands of unknown dependencies in every project. What can be done? I don't know. (Before I'm labeled as entitled -- I spend a lot of time on open source, without the unprofessional behavior.) |
|