Replacing package dependencies to own your code.
Supply-chain attacks forced the issue, but owning your code was always the goal. With the right guidance, AI finally makes it achievable.
Supply-chain attacks were the catalyst, but owning your code was always worth it. We should have targeted that value before bad actors forced the issue. With proper guidance, AI finally makes it achievable.
The catalyst was supply-chain risk
Recent supply-chain attacks made the cost of unowned code impossible to ignore. That was the push, but it should not have taken a threat.
Ownership was always the value
Owning your code has always paid off in clarity, control, and security. We should have pursued it on principle, not under pressure.
You can own more than you think
Owning a dependency is cheaper than it looks. A junior recently replaced dotenv, our configuration loader, by hand in about two hours, a story we tell in hiring juniors and teaching the fundamentals. The sequence is the point: you learn to own code without AI first, then apply the same principles with AI tools on a production team, effective because the foundation is already there. AI widens the range to the larger dependencies that once felt untouchable. It does not replace the discipline, it scales it.
Beyond packages
The same instinct applies to framework complexity and inefficiency. If you cannot answer 'do you know what that abstraction does?', it is a liability, not a convenience.
Related: Software Engineering · Compliance & Security