3 ms·
You could but you would be doing yourself two disservices by trusting vendors that aren't providing security updates for dependencies in a timely manner and run
by tofflos 5y ago
You could but you would be doing yourself two disservices by trusting vendors that aren't providing security updates for dependencies in a timely manner and running applications on top of dependencies they haven't been tested with.
Vendors could ship applications with dependencies and package managers could tell which of those applications and dependencies have vulnerabilities. This would clarify the responsibility of vendors and pressure them to provide security updates in a timely manner.
One big obstacle is that it's fairly common for vendors to take a well known dependency and repackage it. It's difficult to keep track of repackaged dependencies in vulnerability databases.
- drran 5y agoWhat vendors? SCO UNIX? HP-UX? IBM AIX?