Comment on Do you actually audit open source projects you download?

<- View Parent
treadful@lemmy.zip ⁨1⁩ ⁨week⁩ ago

Contributors is my favorite metric. It shows that there are lots of eyes on the code. Makes it less likely of a single bad actor being able to do bad things.

That said, the supply chain and sometimes packaging is very opaque. So it almost renders all of that moot.

source
Sort:hotnewtop