lemmydividebyzero@reddthat.com to Technology@lemmy.worldEnglish · 6 days agoEvery dependency you add is a supply chain attack waiting to happenbenhoyt.comexternal-linkmessage-square7linkfedilinkarrow-up174arrow-down10cross-posted to: programming@programming.dev
arrow-up174arrow-down1external-linkEvery dependency you add is a supply chain attack waiting to happenbenhoyt.comlemmydividebyzero@reddthat.com to Technology@lemmy.worldEnglish · 6 days agomessage-square7linkfedilinkcross-posted to: programming@programming.dev
minus-squareearthworm@sh.itjust.workslinkfedilinkEnglisharrow-up14·6 days ago The careful reader may note that my title is not quite accurate. It’s not every dependency you add that’s a problem; it’s every dependency you update. Why not put that in the title, Mr. Hoyt?
minus-squarerenegadespork@lemmy.jelliefrontier.netlinkfedilinkEnglisharrow-up13·6 days agoEvery dependency you don’t update is a zero day waiting to happen. All software carries risk.
Why not put that in the title, Mr. Hoyt?
Every dependency you don’t update is a zero day waiting to happen. All software carries risk.