nivida / web3.ts

POC for a Web3 Lib
9 stars 2 forks source link

Third party dependencies (Security) #24

Open nivida opened 4 years ago

nivida commented 4 years ago

The goal would be to lower the number of third party dependencies to a minimum (the same as Richard is doing with the new ethers version). But because I know Richard well (also personally) can we definitely use the packages from him. This because the existing trust base we have with him is enough big. Any other dependency has to get checked deeply and does have to be implemented on our own if any uncertainty exists.

Note: Don't forget about SES, lavamoat, and object capabilities.