3 ms·
What don't you like about a project needing dependencies?
by Someguy1098 3y ago
What don't you like about a project needing dependencies?
- evanjrowley 3y agoThere is a belief that risk of vulnerabilities introduced by insecure package ecosystems goes up with the number of dependencies. For example, a study on this was recently conducted for PyPI. https://arxiv.org/abs/2309.11021 https://arxiv.org/abs/2309.11021
- Someguy1098 3y agoBut it's inside the Docker container so even if a dependency was compromised it's in a separate userspace and chrooted so unless theres a docker zero day it should be pretty secure still it seems like. An updated Docker environment is pretty secure I think.