Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> There's nothing in place to stop a dependency from putting unsafePerformIO on blast.

     import safe MyDependency
... but do you have to make sure that nothing in the tree is claiming to be Trustworthy. Which is actually pretty easy.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: