@dylancode have to admit, having lots of dependencies from a public repository means having to spread your trust thin. It becomes a very large attack surface.
But people seem to like to work this way, and the only real solution is to modify people's behaviour, which is, for all intents and purposes, impossible.
So all you can do is limit your own dependency use, and/or be in control of as many dependencies as possible.
