3 ms·
Most project dependencies management process is flawed. We shouldn't blindly upgrade modules/deps minor or patch versions to latest with a single command. SemV
by alexandre_m 3y ago
Most project dependencies management process is flawed.
We shouldn't blindly upgrade modules/deps minor or patch versions to latest with a single command. SemVer encourages this, but we should be more careful.
The software supply chain for a lot of OSS is flawed as well. We need software signatures, and less central artifact registries that can be compromised easily.
I don't have a perfect solution for all these problems. Rewriting code instead of relying on external deps, vendoring, automated vulnerability scans, higher scrutiny for all external code, and tighter processes for code management.
- cortesoft 3y agoI somewhat agree on principle, but at the same time, it is hard enough keeping ur software patched and up to date already, adding more friction to that process may cause more damage than it prevents. You might prevent malicious new code at the cost of running old vulnerable code longer.