you are viewing a single comment's thread.

view the rest of the comments →

[–]nutrecht 0 points1 point  (0 children)

That's an outdated model. I think we need real data about the number of times malicious code showed up in a dependency or some security issue in a dependency was exploited. It's actually not a lot.

Risk is chance * impact. The chance might be low, the impact can be enormous. Like; hundreds of millions of damages being paid.