Follow

RT @kiraemclean
Ask yourself before including new dependencies:
- can you really not do this in a few lines of code yourself?
- do they regularly scan for known vulnerabilities?
- do they accept outside PRs to bump deps?
- how many downstream deps does it have? what kind of shape are they in?

Sign in to participate in the conversation
CleverLibre Social

CleverLibre Social is an inclusive social instance for open discussion, learning, and community.
All cultures welcome.
Hate speech and harassment strictly forbidden.