| ▲ | dhamidi an hour ago | |
> So an engineer who knows your codebase and tests can sneak in malicious code/backdoors because you're high trust. What is the alternative? Bumping a dependency in a PR and getting a LGTM can also introduce a backdoor. That's another form of high trust: your trusting the publisher of the dependency. High trust comes with high responsibility, which is easier to enforce when the trusted party is an individual on your team with generally aligned incentives, rather than an organization or unpaid individual on the internet serving many. | ||