• AwesomeLowlander
    link
    fedilink
    English
    -123 days ago

    It’s an imported library, since when are devs expected to be inspecting the source code of every library they import?

    • yessikg
      cake
      link
      fedilink
      522 days ago

      Since forever? Don’t you do security audits on the libraries you use?

      • AwesomeLowlander
        link
        fedilink
        English
        122 days ago

        One person from the team, maybe. You don’t have every single dev read every line of code in the libraries, which is what is being specified here