4 ms·
This argument is also a holdover from a time where supply chain attacks weren't considered a serious threat.
by dchftcs 4y ago
This argument is also a holdover from a time where supply chain attacks weren't considered a serious threat.
- porcoda 4y agoExactly. The single biggest hurdle for me using some open source tools written with newer languages is the ridiculous dependency surface due to a preference for package repositories over curated “batteries included” bundled libraries. I work in an environment that is hyper sensitive to supply chain integrity, which means a lot of languages that have a culture of “use all the third party packages” are out for us. Give me a batteries included standard library please - much easier to audit and track.
- bitwize 4y agoNearly every place I've worked, the supply chain attack problem has been solved or at least mitigated by using an Artifactory instance with a curated list of packages.