we_are_coded.by CODE · The world, decoded
БГ
Concept

Library and framework

The BasicsUpdated on 16 August 2026we are coded

No one builds an app from scratch. Understand what programmers buy ready-made - and why a hole in a single piece hits thousands of products at once.

Checked on16 August 2026
In short: no app you use was written from scratch. It's assembled from ready-made pieces written by other people. One such piece is called a library. A whole ready-made foundation you build on top of is called a framework. That's why a hole in one popular piece can hit thousands of unrelated products at the same time.

Code is a list of instructions that make the phone or computer do something - open a photo, check a password, show the weather outside. Anyone building an app has to write an enormous number of such instructions. Instead of inventing every one from scratch, they go to something like a hardware store for ready-made parts. They buy a ready-made lock for the door, instead of forging it themselves. In software, that ready-made lock is called a library - someone else's code, written by another person, for one specific job.

When you sign into an app with the "Sign in with Google" button, the bank or the shop didn't write that button themselves. They took a ready-made library that does exactly that job: checks who you are through your account with Google. With one piece of someone else's code, they save themselves months of work.

A framework is a bigger thing than a library - a whole ready-made structure: walls, floor, roof, pipes already run through it. The builder doesn't lay brick by brick. They get the frame and furnish the rooms inside. Most sites and apps you see every day stand on exactly such a borrowed framework.

Here's the catch. Once thousands of apps use the same ready-made lock, a hole in that lock isn't a problem in one place. It's a hole in the doors of thousands of houses at once. That's why, when you hear about a breach in a library, behind it isn't one shop - it's a chain of shops that all bought the same defective lock.

The product you use is never the work of only the company whose logo sits on top. It's an assembly of other people's hands, ones no one outside even suspects.

Who actually wrote it

This logic has been familiar to me for a long time, long before AI. When I do a project at CODE, I never cut tiles from raw material myself - I buy ready, tested parts and arrange them so the result looks entirely mine. Software works the same way, except the ready-made parts are invisible. The client sees the beautiful site. They don't see the hundred foreign bricks underneath.

So when I build my own AI systems, my first question is never whether to write something myself. It's who's already written it, and whether I can trust them. Choosing a ready-made part is a decision about trust, not laziness.

The visual is generated code art. No third-party images.
Official primary sources
→MDN Web Docs: Introduction to client-side frameworks (Mozilla)