▲ | bakkoting 4 days ago | |||||||||||||
> And how many dependencies does Hono have? Zero. I'm guessing you're looking at the `devDependencies` in its package.json, but those are only used by the people building the project, not by people merely consuming it. | ||||||||||||||
▲ | PxldLtd 3 days ago | parent [-] | |||||||||||||
That doesn't prevent supply chain attacks. Dev dependencies are still software dependencies and add a certain level of risk. | ||||||||||||||
|