Snippet · Shipping & running it
Audit what you installed
You are running all of it, whether you read it or not.
Here is my dependency list: <paste package.json / requirements.txt> For each one, tell me: - What it does, in one line, and which of my features needs it. - Whether it's actively maintained. - Whether I could drop it for a dozen lines of my own code. Then flag: anything I appear not to use at all, anything with a known advisory, and any two packages doing the same job.
Every dependency is code you ship without reading, updated by someone you have never met. Fewer is genuinely safer.