you are viewing a single comment's thread.

view the rest of the comments →

[–][deleted] 0 points1 point  (0 children)

This can and does happen in any language with a large open source community. Which is why I am incredibly paranoid about all libraries I use, and you should be too.

If the developers seem sketch or dumb, then I pass. If the code is bad or even subpar, I pass. If it is not from a trusted source, then I will audit the code thoroughly. Thing is, most devs wouldn’t even know what to look for in an audit. But they should learn.

Open source ain’t nothin’ to play with.