My code depends on a library that makes liberal use of patching (replacing text in source code) for its own dependencies. I feel this is bad form, because, for example, that dependency may now conflict irreconcilably with another dependency of mine.
Am I right in thinking patching code is bad form?


Bad form. Breaks SLSA some. Breaks some CVE tracking tools too.
If the patch introduces a vulnerabilty or breaking issue how would it be tracked?