2 ms·
Good question. We take this seriously, and try to keep the dependency footprint small (which is a challenge in the node/npm ecosystem). We try to stick with l
by brown 4y ago
Good question. We take this seriously, and try to keep the dependency footprint small (which is a challenge in the node/npm ecosystem). We try to stick with large, battle-tested dependencies (express, react, etc). For less popular projects, we will clone and run and perform our own internal audit.
We also follow best practices with automated tools like Sonar and Dependabot to automatically scan dependencies. We've gone through multiple pen tests. There's no silver bullet though, so it's a constant battle.