4 ms·
I'm not sure what point you are making. Yet, reviewing hundreds of thousands SLOCs (across different languages) and also checking legal compliance requires sig
by ex_amazon_sde 6y ago
I'm not sure what point you are making.
Yet, reviewing hundreds of thousands SLOCs (across different languages) and also checking legal compliance requires significant skills, time and efforts.
As an individual, you cannot justify reviewing the entire dependency tree across all your projects.
Thankfully you can rely on the packages reviewed and built internally by your colleagues - or use a Linux distribution that does thorough vetting.
- itake 6y agoAmazon probably builds everything in house. Smaller shops rely more on open source tools like npm or Ruby gems. I think there are supply chain attack vectors in those resources