3 ms·
This is one of the gaping security holes that open source has always had, you don’t know where the code came from and your best indication if it’s safe is how p
by jamp897 8y ago
This is one of the gaping security holes that open source has always had, you don’t know where the code came from and your best indication if it’s safe is how popular it is. Npm and Maven libs being the scariest since there are hundreds for even small apps.
- syn0byte 8y agoAre those points not the same for closed source products? "You don't know where the code came from" and "your best indication if its safe is how popular it is."