Comment Re:Remotely downloaded code (Score 1) 19
Are the benefits of using tools like composer worth these risks? Why is that still the norm, rather than the exception?
Because 1) handling exceptions is hard and 2) keeping everything updated from the myriad of sources is hard too.
Whether the benefits are worth the risks is surely complicated, but if it means updates get done that otherwise wouldn't (and it does) then there's at least a reasonable chance that it's a net positive overall.