• magic_lobster_party@fedia.io
    link
    fedilink
    arrow-up
    39
    ·
    2 days ago

    it’s the kind of dependency developers install without a second thought

    I got a feeling this is an attack vector that will continue to grow, as now there’s vibe coding frameworks installing random dependencies without a thought at all.

    • corsicanguppy@lemmy.ca
      link
      fedilink
      English
      arrow-up
      9
      arrow-down
      1
      ·
      2 days ago

      There’s twonthings at play, here:

      • installing dependencies without checking
      • a framework that will allow this

      Both are absolutely the fault of the user.