Posted April 23, 2021
Timboli: That said, I have downloaded thousands of programs from the web over the years, and some of them have been very wonderful. If I needed to audit each one, that would never have happened. Life is about reasonable risk.
I'm a devops engineer (the responsability to make sure our dependencies check out ultimately fall on my shoulders) and I can't say I look at the code for all our dependencies. Will I inspect less well used dependencies we have? Of course.
Will I audit the code base from EVERY dependencies we have (including foundational technologies like kubernetes, terraform, postgres, nodejs, python3, etc)? No, if I did that, I might as well change my title to "code inspector".
At some point, you need to use your common sense.
Even taking any consistency of character, moral, consideration out of the equation: In my case (and the case of most prolific people on github), I have a professional reputation to protect. Would I mess up a livelihood that I prepped up with an insane amount of unpaid work over almost 2 decades just so that I could hack random people's computers (something that wouldn't even be subtle given an open codebase)? It wouldn't make a whole lot of sense.
Post edited April 23, 2021 by Magnitus