8 ms·
It doesn't have to be. Corporations which are FedRAMP[1] compliant, have to build software reproducibly in a fully isolated environment, only from reviewed code
by acatton 3y ago
It doesn't have to be. Corporations which are FedRAMP[1] compliant, have to build software reproducibly in a fully isolated environment, only from reviewed code.[2]
[1] https://en.wikipedia.org/wiki/FedRAMP https://en.wikipedia.org/wiki/FedRAMP
[2] https://slsa.dev/ https://slsa.dev/
- metadat 3y agoIn theory, yes. Who has really reviewed and analyzed every line of Kafka or Spark? Even the bigcos.. don't.
- Nursie 3y agoAh, I remember when we all did that. It was just part of basic due diligence - pull all your dependencies into your own build system, review and check compatibility, then build completely locally. Of course a lot of what we built wasn’t public facing or exposed to the internet at all, so addressing the latest vulnerabilities in record time wasn’t quite as important as known-good builds. I’ve worked in one or two places recently (big bank) that are large enough to have their own internal repo systems and teams of security/compliance reviewers. Their versions of things can be a bit behind but are at least under control of the same org. Everywhere else, well, it feels a bit like cowboy country… (edit - the other trade-off was of course that you wrote a lot more of everything yourself, rather than pulling in whatever you felt like. This slows down the development cycle significantly but it does mean people had a greater understanding of everything in their stack, and products were often more lean as a result.)