Do you trust packages you download from package repositories such as npm, PIP, Nuget etc?
Survey period: 27 Sep 2021 to 4 Oct 2021
CocoaPods, cargo, gems, PIP, npm, NuGet, Conan. There's a package repository for everyone these days.
Yes, I always trust packages downloaded from the major package repositories | 98 | 13.48 | |
I generally trust them, but I'm still careful | 247 | 33.98 | |
I trust them if I can take a peek at the source code | 34 | 4.68 | |
It depends on lots of things. There's no yes/no answer here | 213 | 29.30 | |
I don't generally trust packages from these repositories | 23 | 3.16 | |
I never trust the code from these repositories | 15 | 2.06 | |
No comment: I never use package repositories | 97 | 13.34 | |
© 2021 The Code Project. All rights reserved.
This email was sent to vutunglampro@gmail.com. To stop receiving The Weekly Newsletter click here.
CodeProject 20 Bay Street, 11th Floor, Toronto, Ontario, Canada M5J 2N8 +1 (416) 849-8900 Please do not reply directly to this email. It was sent from an unattended mailbox. For correspondence please use webmaster@codeproject.com
Không có nhận xét nào:
Đăng nhận xét