    In a sense we do have these for safety critical issues, such as aviation-grade software.

    I would hate for all software to be subject to a general fire code.

      I see where you’re coming from, but how would one solve the problem of building fire-code proof software out of dependencies that aren’t fire-code proof?

      Modern software is not built in isolation, but highly dependent on external libraries and other packages. See also this recent Lobste.rs post and of course the recent log4j consternation.

        The answer is simple. You don’t use those deps in safety critical software.