3 ms·
But then did you check every one of their dependencies?
by mowse_winded 3y ago
But then did you check every one of their dependencies?
- lmm 3y agoWe treated transitive dependencies the same as any other dependencies (i.e. they had to have an owner and be audited etc.). We didn't audit our suppliers' build toolchains or vendored dependencies, but would've considered them responsible if something malicious came in that way.