On two previous occasions I have written on the risks posed by the inclusion of third party packages, irrespective of the technology stack, and some measure that can be taken to guard a project using NPM packages.

Poorly managed packages considered harmful

An NPM dependency check list

In recent weeks I have become aware of discussions on whether developer should read AI-generated code or not. Of course the answer is it depends.

For my two-penn'orth, in many environments the developer is considered responsible for the code they publish. In deed, I have long held the position that a good Software Engineer views it as their responsibility to own all the code they release.