Sick of "many dependencies" framing
Sick of "many dependencies" framing
Posted Feb 11, 2026 7:29 UTC (Wed) by mjg59 (subscriber, #23239)In reply to: Sick of "many dependencies" framing by taladar
Parent article: FOSS in times of war, scarcity, and AI
Not really - the more maintainers I need to trust, the higher the probability that one of them is either malicious or is compromised in some way. Personally I think this is a reasonable tradeoff, but there's still some degree of additional attack surface as a result.
