5 ms·
These days I find it hard to trust the many dependencies installed by language-level package managers. OS-level system package managers tend to do better, but t
by equalunique 7y ago
These days I find it hard to trust the many dependencies installed by language-level package managers. OS-level system package managers tend to do better, but they too have also had incidents.
- geofft 7y agoThen why do you have them installed? Surely you're not using those dependencies you don't trust as actual dependencies of your server application, are you?
- a1369209993 7y agoFraudulent transitive dependencies. My application depends on libuseful version 1 or later. libuseful_1 depends on libtiny, but libuseful_2 depends on libbigballofmud, which consists of libtiny and 800 other libraries that have been merged together for political reasons. libuseless, which was also merged into libbigballofmud, depends on rce-daemon, or nvidia-brick-the-install, or systemd, and I've never heard of rce-daemon before, so it's not blacklisted and installs with no error message. As the other two options suggest, this is not hypothetical.
- majewsky 7y ago> nvidia-brick-the-install Is this in reference to when the nvidia driver had sudo rm -rf /usr /lib/something/something in its install script?
- a1369209993 7y ago... I'm not actually surprised. But no; my desktop machine has a video card that doesn't display anything (black screen) if booted with the non-legacy nvidia drivers. I had to boot off a old 32-bit install to get rid of them and then wrestle apt/dpkg back into a sane state.
- majewsky 7y agoAh right, yes, NVidia frequently drops support for old models in their newer driver releases. I'm so happy I have left that world behind, with both my PC and notebook using AMD GPUs.
- vbezhenar 7y agoIf you have compromised dependency, spectre is the least thing you should worry about IMO.