4 ms·
Software went from DLL Hell [1] to Dependency Hell [2]. Only now there is a dependency war so it is much more dangerous, and so many more dependencies. Dependa
by drawkbox 4y ago
Software went from DLL Hell [1] to Dependency Hell [2]. Only now there is a dependency war so it is much more dangerous, and so many more dependencies.
Dependabot has to be used because of the threats. However everyone automating and moving to latest is also a threat. SolarWinds/VMWare/USGov hack [3] was all related to CI builds and automated "trust", ended up infecting tens of thousands of systems that thought they were secure with SOC2. SOC2 ends up making enterprises "trust" many third parties. What happens when dependabot is an attack vector as well...
The log4j/Log4Shell [4] issue shows how long exploits can go on without detection or automated fixes. Node is filled with dependency issues and that is just the known exploits besides all the "telemetry". [5]
Any third party or dependency is a potential attack vector, and dependency saturation is adding lots of tedium to shipping. So much time goes to just updating libs it is a bit of a tragic comedy.
[1] https://en.wikipedia.org/wiki/DLL_Hell https://en.wikipedia.org/wiki/DLL_Hell
[2] https://en.wikipedia.org/wiki/Dependency_hell https://en.wikipedia.org/wiki/Dependency_hell
[3] https://en.wikipedia.org/wiki/2020_United_States_federal_government_data_breach https://en.wikipedia.org/wiki/2020_United_States_federal_gov...
[4] https://en.wikipedia.org/wiki/Log4Shell https://en.wikipedia.org/wiki/Log4Shell
[5] https://en.wikipedia.org/wiki/Npm_(software)#Notable_breakages https://en.wikipedia.org/wiki/Npm_(software)#Notable_breakag...