We are conservative about adding dependencies. The default answer is no — every package is a long-term liability, not a free win.
When we do add one, we prefer well-maintained projects with a permissive license, a security policy, and a real release cadence. We mirror critical dependencies into our own registry so a third-party outage can't take production down.
We audit our dependency tree monthly and update the things that matter weekly.
