4 ms·
Google does something similar and really this is sensible for any organization of sufficient size. When I was there (I believe) they had a security team review
by ford 5y ago
Google does something similar and really this is sensible for any organization of sufficient size. When I was there (I believe) they had a security team review any new third party library, and once reviewed they would copy the entire source code into their monorepo.
Fortunately Google is large enough that having a net-new dependency was quite rare.
- froh 5y agoThat's also what the large and maintained Linux distro s do: do an in depth review of any security critical patches, put a security aware maintainer on the package and maintain an authenticated copy of the source code.
- kragen 5y agoCommonly they accept patches from upstream without reviewing them. If Artifex were to slip malware into the next version of GhostScript or Google were to slip malware into the next version of Chrome, probably nobody at Debian would notice.
- froh 5y agoSLES and rhel don't simply add patches from mainline. For Ubuntu I hope it's the same. And even in the community distros you have maintainers. All professionally managed packages, kernel, libc, gcc/llvm postgres, python, etc etc have full time professional mainline maintainers. And package maintainers with a high working ethos as reviewers and gatekeepers. The problem is with leaf packages in ginornous self serviced blindly trusting huge repos like pip or cargo or younameit, npm, with huge numbers of tiny packages with no tangible responsibility whatsoever.
- kragen 5y agoHmm, are you saying Red Hat has someone who reviews every line of code Google adds to Chromium and every line of code Apple adds to LLVM? And who will refuse patches they aren't confident in? That's not impossible but it definitely isn't my understanding of how Red Hat works.