← Back to context

Comment by kentm

2 days ago

It really is amazing to me how many developers do not understand that governance is important. If I have a dependency and a maintainer of that dependency has a process I can’t trust, it’s perfectly valid to remove that dependency based on that lack of trust.

Not caring about governance is how we end up with repeated supply chain attacks.