Hacker News new | ask | show | jobs
by kentm 28 days ago
It really is amazing to me how many developers do not understand that governance is important. If I have a dependency and a maintainer of that dependency has a process I can’t trust, it’s perfectly valid to remove that dependency based on that lack of trust.

Not caring about governance is how we end up with repeated supply chain attacks.