1
0 Comments

Fear Is the Mind-Killer. Dependencies Are the Build-Killer.

The recent Shai-Hulud npm supply-chain attack is a good reminder that every dependency is something you're trusting with your code, your build, and potentially your credentials. The answer isn't "never use dependencies." That's silly. We'd all still be writing our own HTTP clients.

Instead:

  • Minimize dependencies.

  • Pin them to specific versions.

  • Audit direct and transitive dependencies.

  • Remove packages you don't need.

  • Use trusted package sources.

  • Keep CI/CD credentials locked down.

And yes, FeatureFlags.app is itself a third-party dependency. We're not pretending otherwise. That's why the client library is intentionally small and open source, so you can actually see what you're putting into your application.

posted toAvatar for product FeatureFlags.app
FeatureFlags.app