Skip to main content

You are not logged in. Your edit will be placed in a queue until it is peer reviewed.

We welcome edits that make the post easier to understand and more valuable for readers. Because community members review edits, please try to make the post substantially better than how you found it, for example, by fixing grammar or adding additional resources and hyperlinks.

Required fields*

3
  • Good point, but should be noted that there are ways, such as npm audit and snyk, to do much of the security checking in a more automated way.
    – user949300
    Commented Dec 28, 2018 at 18:55
  • 2
    Those tools are just checking for known vunerablities. Not deliberately introduced backdoors and the like
    – Ewan
    Commented Dec 28, 2018 at 20:17
  • And "deliberately introduced backdoors" are a new vector only beginning to be exploited. This is the future. Commented Dec 29, 2018 at 17:29