3 ms·
I would go as far as saying anyone who does not have control and awareness of their dependencies is asking for trouble. VM be damned.
by _eht 6y ago
I would go as far as saying anyone who does not have control and awareness of their dependencies is asking for trouble. VM be damned.
- akira2501 6y agoThat's part of the reason I feel uncomfortable with "modern" package systems like golang's. I really want to use golang more, but I just don't feel 'secure' about building a bunch of packages pulled off of github by URL.
- _eht 6y agoThird-party package management is not a modern marvel by any means. You are unnecessarily singling out golang, and if you let that stop you from learning it's your loss. Just be smart. Dependency awareness is not black magic.
- jatone 6y agoodd golang has a better security story than npm, rubygems, and python. it'll at least crypto ensures the dependency code hasnt been modified since you first retrieved it iirc. the rest is up to you as a developer to ensure its safe.