For example, I'm currently writing my own graph layout library because I'm not happy with Dagre and ELK.
For example, I'm currently writing my own graph layout library because I'm not happy with Dagre and ELK.
Your custom library probably won't fall to a library-specific attack unless you were actively aiming for interoperability. However your custom library almost certainly has many vulnerabilities that you haven't heard of yet. Just a few weeks ago I saw a custom library (PHP) with SQL injection vulnerabilities, I couldn't believe it. I suggested to the client that if he still resists having another professional audit it, at least let some frontier LLM have a look. Yes, I recommended this guy to vibe code his security-sensitive code because "professional developers" today still miss the basics.
Amen. Nowadays it is borderline malpractice to not use a coding agent for checking the security of your code.
Need a few math operations? pull those in, instead of an entire math lib, for example.
I've always liked writing my own libraries and minimal frameworks for PHP, which seems to be a very unpopular opinion, but it almost entirely removes churn from your stack, which is nice for tools that may stick around for years or decades. I also never switched off jquery, preferring simple techs. I'm almost definitely operating at a smaller scale than most web developers here, though.
In spite of my above-stated preference, I used Django for my most-recent project, and don't regret that decision a bit.