Supply-chain attacks were the catalyst, but owning your code was always worth it. We should have targeted that value before bad actors forced the issue. With proper guidance, AI finally makes it achievable.

The catalyst was supply-chain risk

Recent supply-chain attacks made the cost of unowned code impossible to ignore. That was the push, but it should not have taken a threat.

Ownership was always the value

Owning your code has always paid off in clarity, control, and security. We should have pursued it on principle, not under pressure.

You can own more than you think

Owning a dependency is cheaper than it looks. A junior recently replaced dotenv, our configuration loader, by hand in about two hours, a story we tell in hiring juniors and teaching the fundamentals. The sequence is the point: you learn to own code without AI first, then apply the same principles with AI tools on a production team, effective because the foundation is already there. AI widens the range to the larger dependencies that once felt untouchable. It does not replace the discipline, it scales it.

Beyond packages

The same instinct applies to framework complexity and inefficiency. If you cannot answer 'do you know what that abstraction does?', it is a liability, not a convenience.

Related: Software Engineering · Compliance & Security

Get in touch

Bring us the hard problem.

Tell us where you're headed. We'll map what's possible, then build it.