Reply to post:

When one open-source package riddled with vulns pulls in dozens of others, what's a dev to do?

Phil O'Sophical Silver badge
Flame

if a developer is pulling in unchecked and untested third-party packages, and including them in a 'product' that is shipped to their customers, then that developer should face the full force of any legal penalties incurred by their customers due to the developer's incompetence.

If an aircraft manufacturer bought components from a supplier, and just installed them without consistently checking they they met the safety specs, would they get away with saying "not my fault, blame my supplier"?

It isn't 'agile', it's 'lazy'.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon