Comment by traceroute66
4 hours ago
> Most people can't justify the time commitment needed to read and then modify the code for tools they use very often.
A lot of modern open source software is often written in dependency heavy languages.
So to do a "proper" examination, by definition you need to consider the dependencies as well as the core code itself. We all know how supply-chain attacks are on the rise.
No comments yet
Contribute on Hacker News ↗