2 ms·
> Static linking, dependency pinning and bundling are three bad practices that have serious impact on the time and effort needed to eliminate vulnerabilities fr
by cuillevel3 6y ago
> Static linking, dependency pinning and bundling are three bad practices that have serious impact on the time and effort needed to eliminate vulnerabilities from production systems.
I'm astonished how different this perspective is. As a developer I see that software is developed faster nowadays. size, library reuse and functionality are increasing.
And distributions are just not able to keep up.
I feel like they never did, they just made exceptions for packages that were too important to ignore, like browsers or office suites.
Really, it's not the software. It's the distros.
Not using libraries is not an option, you don't want devs to write their own crypto.
Not pinning dependencies is bad, incompatibilities and security issues could make their way into the code. The test surface also gets bigger and it raises the question which combinations are supported.
Update: I think what I want to say is, distributions should accept that they can only provide that level of "stability" for a limited set of applications. The new and shiny stuff will always happen elsewhere.