Post #3138562
2025-08-28 04:22 UTC
@joshbressers@infosec.exchange being dependent on russian code is a security risk, you can't guarantee freedom of expression in a country known to disappear people with wrong political positions.
if everybody does that it doesn't mean that it's safe and "popularity" of single person maintained open source solutions does not in any way hint at their security characteristics
if one person can maintain that code why just not embedded it directly in your repository? be a man, manage your f*cking js modules
Replies (1)
-
@Natanox@chaos.social 2025-08-28 07:41
@gonzo_askold@mastodon.social @joshbressers@infosec.exchange Unfortunately by now the same applies to projects maintained from the US (and obviously also China). Even though people are usually still traceable im the first, they can't work on anything from within Prison or ICE detention. Don't think country-based scrutiny of trust in developers works anymore these days. I agree that you should properly manage your god damn dependencies, of course.