Yes, but it uses a massive number of libraries that were not developed at Facebook.
> But yes, with an increasing amount of dependencies the process of updating such needs more effort as well. But then, we can postpone such updates, if the application under development is safety critical...
Postponing dependency updates is very, very bad for security. That is not a solution to supply-chain attacks.
> Well, one should be able to judge about the workings imo. Otherwise maintainability can get painful in the long run.
The whole point of APIs is that we do not need to understand the inner workers of code that we're calling. How many of us use bcrypt and couldn't tell you anything about the underlying algorithm?