Hacker News new | ask | show | jobs
by baq 176 days ago
still need to read them to make sure you don't vendor a trojan in the first place.
1 comments

auditing is the first step in vendoring a dep by my definition of the practice