4 ms·
Yes, you can patch them but with a compiled binary like go, you don't have to. You don't have to watch security lists for vulnerabilities. You don't have to s
by cbushko 6y ago
Yes, you can patch them but with a compiled binary like go, you don't have to.
You don't have to watch security lists for vulnerabilities.
You don't have to scan your docker containers because the dockerfile is 4 lines long.
You don't have to worry about a coworker adding a bad tool to your production container.
That frees up cognitive load to write your code.
Note: I am an infrastructure engineer for a small SaaS that builds and runs production.
- acdha 6y ago> Yes, you can patch them but with a compiled binary like go, you don't have to. > You don't have to watch security lists for vulnerabilities. These two statements are incompatible. You have fewer things to watch but you’re definitely still going to track your dependencies. Static linking still means you have to do that, and nobody else can do it for you.
- cbushko 6y agoNot exactly. You have to watch your libraries for vulnerabilities no matter what language you use. Link or apt-getting the library will pull in a vulnerability I am more concerned about pulling in Linux binaries that are full of vulnerabilities.
- acdha 6y agoThis is a valid concern but in general you should be most worried about code you actually run. If you have curl in a container but your app only uses it during the startup process, the fact that it has an issue with, say, FTP almost certainly has no effect on you. OTOH, if you’re using something like libjpeg your Go code needs to be recompiled either way and you might have to manually backport a patch just like a Linux distribution will.