The ‘Trusted Dependency’ is a Lie. Here’s What Developers Should Do Instead.
Every developer knows the anxiety of installing an unfamiliar package. We cross our fingers and hope a single compromised dependency doesn’t brick our machineโor worse, compromise our users. Drop rethinks this trust model. Itโs a rootless Linux sandbox that merges the disposability of Python’s virtualenv with strict, enforced isolation. Instead of stripping away your tools like a VM, Drop mounts your configs read-only and traps the threat. The goal isn’t to trust the right packages; it’s to make trust irrelevant.