4 ms·
>>C++/boost could have a bad actor upload malicious code. The only difference is that people probably wouldn't notice for months, because everyone's running dec
by fivea 5y ago
>>C++/boost could have a bad actor upload malicious code. The only difference is that people probably wouldn't notice for months, because everyone's running decades old versions of boost anyway. Not because they're mindful of security, but because nobody can bother to update it unless the need becomes dire.
This baseless assertion is quite wrong and completely detached from reality. Boost is not a one-man show which is a git commit away from disaster. Boost is a commmunity-driven project where any change to an existing package is subjected to a public review and proposals for new components are performed through a submission process.
https://www.boost.org/users/faq.html https://www.boost.org/users/faq.html
- spoiler 5y agoI write C++ (for better or worse), and I know Boost is an algamation of libraries and many hard working maintainers. I didn't mean to imply anything bad about boost. I think you misunderstood me because I gave a poor example. I'm talking about the general/average mindset of the C++ community when it comes to updating dependencies. Also the way dependencies are "managed" (or lack of it) in virtually every project. The HN crowd isn't considered "average" in that dimension, probably. So even if you yourself have a culture of keeping things updated with Conan or whatever, it's definitely not the status quo.