Ask HN: Why do people trust just about any bit of open source code?
Why is this?
Why is this?
All of this happened because Guzzle devs followed some obscure standard that required you to set the proxy by the env var HTTP_PROXY. And another "standard" putting any headers set in a request as env var variables prefixed with HTTP_*
I guess what I am trying to say here is that eventhough an author may have good intentions, it can still cause bad things to happen. You should always scrutinize dependencies, but I think most rarely do.
You realize that the open-source code you use has hundreds of stars on GitHub, tons of independent people providing edge case and bug feedback. For all of those people to be bad actors is unlikely. If something was malicious about it, that information would spread through the web like wildfire, and you would know about it.
This is why people are reluctant to use libraries which are not well-known or have very little usage feedback. If you do use these libraries, you will probably read the source code first.