3 ms·
You have not been in the field very long than I presume? There's multiple per year that require all hands on deck depending on your tech stack. Just look at the
by wowohwow 10mo ago
You have not been in the field very long than I presume? There's multiple per year that require all hands on deck depending on your tech stack. Just look at the recent NPM supply chain attacks.
- mjr00 10mo agoYou presume very incorrectly to say the least. The npm supply chain attacks were only an issue if you don't use lock files. In fact they were a great example of why you shouldn't blindly upgrade to the latest packages when they are available.
- wowohwow 10mo agoFair enough, which is why I called out my assumption:). I'm referring to the all hands on deck nature of responding to security issues not the best practice. For many, the NPM issue was an all hands on deck.
- stavros 10mo agoWait what? I've been wondering why people have been fussing over supply chain vulnerabilities, but I thought they mostly meant "we don't want to get unlucky and upgrade, merge the PR, test, and build the container before the malicious commit is pushed". Who doesn't use lockfiles? Aren't they the default everywhere now? I really thought npm uses them by default.
- Aeolun 10mo agoWe use pretty much the entire nodejs ecosystem, and only the very latest Next.js vulnerability was an all hands on deck vulnerability. That’s taken over the past 7 years.
- procaryote 10mo agoYou solve a bunch of them by not using javacript in the backend though
- threethirtytwo 10mo agoTo add to this conversation from our other thread, you solve a bunch of problems that are nearly just as bad by not using microservices yet you still do. And that is the same reason why people use JavaScript despite the issues it introduces. It’s not like you’re the only person the industry who hasn’t used a technology that irrationally introduces horrible consequences.