4 ms·
I encourage you to read this then: https://go.dev/blog/supply-chain https://go.dev/blog/supply-chain. Edit: along with the authors own blog explaining their ta
by room271 4y ago
I encourage you to read this then: https://go.dev/blog/supply-chain https://go.dev/blog/supply-chain.
Edit: along with the authors own blog explaining their take: https://kerkour.com/supply-chain-attacks-and-backdoored-dependencies https://kerkour.com/supply-chain-attacks-and-backdoored-depe....
The short version is, it's better to have a centralised (though proxyable, and opt-outable) central store of hashes of module content, but then provide flexibility over distribution. The concern is that a central package manager adds complexity and opportunity for security vulnerabilities without adding much value.