On two previous occasions I have written on the risks posed by the inclusion of third party packages, irrespective of the technology stack, and some measure that can be taken to guard a project using NPM packages.
Poorly managed packages considered harmful
An NPM dependency check list
In recent weeks I have become aware of discussions on whether developer should read AI-generated code or not. Of course the answer is it depends.
For my two-penn'orth, in many environments the developer is considered responsible for the code they publish. In deed, I have long held the position that a good Software Engineer views it as their responsibility to own all the code they release.







