# Dependencies are dangerous Page: https://stenobird.com/podcast/go-time-golang-software-engineering/dependencies-are-dangerous Text version: https://stenobird.com/podcast/go-time-golang-software-engineering/dependencies-are-dangerous.md Podcast: [Go Time: Golang, Software Engineering](https://stenobird.com/podcast/go-time-golang-software-engineering) Published: 2024-07-03T20:00:00+00:00 Episode link: https://changelog.com/gotime/321 Audio file: https://op3.dev/e/https://cdn.changelog.com/uploads/gotime/321/go-time-321.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/go-time-golang-software-engineering/episodes/dependencies-are-dangerous Duration seconds: 3817 ## Resource Dependencies! We need them, but how do we use them effectively and safely? In this week's episode Kris is joined by Ian and Johnny to discuss the polyfill.io supply chain attack, the history of dependency management and usage in Go, and the Go Proverb that "a little copying is better than a little dependency". Of course, we wrap up the episode with some Unpopular Opinions! ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/go-time-golang-software-engineering/episodes/dependencies-are-dangerous/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/go-time-golang-software-engineering/dependencies-are-dangerous.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.