Regarding "supply chain security" with dependencies: as a professional dependency auditor I can tell you that malicious dependencies are extremely rare... and what's far more common is security issues in utilities that large dependencies insisted on reimplementing despite safe off-the-shelf options being available.
If your takeaway from dependency security stuff is "avoid dependencies", then that is absolutely the wrong takeaway.
@joepie91 there's a certain amount of hubris with developers who think they can re-implement huge libraries without security, performance, and safety issues.
I mean, I assume these are the same developers fixing their own normal code bugs all day. At least I've never met a developer who didn't have to fix their own bugs all day long.
@rune (Not obvious from the gradient is that basically only 5-7 meet my quality criteria for dependencies, everything below that scores a hard 'fail')