• AwesomeLowlander
    link
    fedilink
    English
    03 days ago

    It’s an imported library, since when are devs expected to be inspecting the source code of every library they import?

    • yessikg
      link
      fedilink
      42 days ago

      Since forever? Don’t you do security audits on the libraries you use?

      • AwesomeLowlander
        link
        fedilink
        English
        12 days ago

        One person from the team, maybe. You don’t have every single dev read every line of code in the libraries, which is what is being specified here