Click here to Skip to main content
15,914,447 members

Survey Results

Do you trust packages you download from package repositories such as npm, PIP, Nuget etc?

Survey period: 27 Sep 2021 to 4 Oct 2021

CocoaPods, cargo, gems, PIP, npm, NuGet, Conan. There's a package repository for everyone these days.

OptionVotes% 
Yes, I always trust packages downloaded from the major package repositories9813.48
I generally trust them, but I'm still careful24733.98
I trust them if I can take a peek at the source code344.68
It depends on lots of things. There's no yes/no answer here21329.30
I don't generally trust packages from these repositories233.16
I never trust the code from these repositories152.06
No comment: I never use package repositories9713.34



 
GeneralFrom and number of downloads Pin
maze328-Sep-21 1:05
professionalmaze328-Sep-21 1:05 
GeneralI guess it depends on what the package does Pin
harvyk027-Sep-21 20:14
harvyk027-Sep-21 20:14 
GeneralOWASP Dependency-Check Pin
RickZeeland27-Sep-21 6:16
mveRickZeeland27-Sep-21 6:16 
GeneralRe: OWASP Dependency-Check Pin
Nelek27-Sep-21 13:57
protectorNelek27-Sep-21 13:57 
GeneralRe: OWASP Dependency-Check Pin
Vikram A Punathambekar29-Sep-21 1:45
Vikram A Punathambekar29-Sep-21 1:45 
GeneralRe: OWASP Dependency-Check Pin
Gary R. Wheeler1-Oct-21 14:14
Gary R. Wheeler1-Oct-21 14:14 
GeneralRe: OWASP Dependency-Check Pin
Vikram A Punathambekar5-Oct-21 1:01
Vikram A Punathambekar5-Oct-21 1:01 
GeneralI probably trust them too much Pin
Lorenzo Bertolino26-Sep-21 23:50
professionalLorenzo Bertolino26-Sep-21 23:50 
GeneralDouble answer Pin
den2k8826-Sep-21 21:46
professionalden2k8826-Sep-21 21:46 
I don't use them AND no, I don't trust them. Not that I could, since 9 times out of 10 the libraries used in my projects need to be certified for safety and security by several entities.

If I'd ever get a package from whoknowswhere and whoknowswho I think management would have a collective stroke. Uhmmm that got me an idea, hold on, brb.
GCS d--(d-) s-/++ a C++++ U+++ P- L+@ E-- W++ N+ o+ K- w+++ O? M-- V? PS+ PE- Y+ PGP t+ 5? X R+++ tv-- b+(+++) DI+++ D++ G e++ h--- r+++ y+++*      Weapons extension: ma- k++ F+2 X

GeneralRe: Double answer Pin
PIEBALDconsult27-Sep-21 8:41
mvePIEBALDconsult27-Sep-21 8:41 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.