4 ms·
Once upon a time, the company I was working at was going through an acquisition and in part of the due diligence process the acquirer asked us for a complete li
by monkeybutton 5y ago
Once upon a time, the company I was working at was going through an acquisition and in part of the due diligence process the acquirer asked us for a complete list of all software and dependencies in our technology stack. The only one my team heard back about was ItsDangerous.
- zachthewf 5y agoWhat did you hear about it?
- monkeybutton 5y agoThey were asking what it was for. I suspect the person reviewing the list had no idea what they were doing. If there's going to be security threat lurking in there its not going to be in the package named "itsdangerous", its going to in the one with a typo in the name.
- asddubs 5y agoon the other hand, just on the off chance that it is malware, you really don't want to be the guy who didn't ask about the package called "itsdangerous"