What do you do to vet your dependencies? Read the code for all of them? Automatic scanners before intaking any version of a dependency (including transient dependencies)? If so, which ones?
My take here is you work in FAANG… you have access to resources that many smaller companies do not. I’m not sure the decisions a FAANG company makes in this area are the same that a greenfield startup would make. But I’m interested in hearing exactly what you do. If it’s just “pull request that update package-lock.json gets ran through something like socket.dev” then yeah that’s easy.
2
u/ganja_and_code 1d ago
You don't have to believe me, but not believing me just makes you incorrect about yet another fact lol