If Socket is willing to flag suspicious packages for us there isn't really a 
downside.

It wouldn't replace any existing security controls and would just be an 
additional layer.

The worst case scenario would be that nothing changes and if it flags even one 
malicious package it's a net positive.

And even if their corporate generosity runs out, we are just back where we 
started. We aren't any less secure than we would be if we never went with them.

I really don't see why we shouldn't give it a try.

-- 
Borna Punda

Reply via email to