|
|
|
|
|
by bdlowery
739 days ago
|
|
I haven’t looked at the source code of a single npm package I’ve installed in the past 5 years. “It takes a few minutes” Dude my web dev projects have like 1,000s of dependencies. I’m not going to check the source code of every package tailwind requires. |
|
A cursory audit of primary dependencies has almost zero chance of catching anything but a brazen exploit.