4 ms·
Debian has had a better "software supply chain" posture than any other player in the ecosystem since before the turn of the century. While we all face the risk
by rlpb 5mo ago
Debian has had a better "software supply chain" posture than any other player in the ecosystem since before the turn of the century. While we all face the risk of malware from upstream, Debian is the least at risk of being affected by it. See for example the stream of issues from npm et al. None of it has affected Debian.
- alkindiffie 5mo ago> for example the stream of issues from npm et al. Curious, what distros where affected by npm supply chain attacks?
- throw_a_grenade 5mo agoIt's npm that's affected, therefore it's not even considered when choosing language/ecosystem for writing distro tools. You'll find no sane distro writing package manager in javascript precisely to avoid this joke of a supply chain.
- skydhash 5mo agoI quite like the OpenBSD approach to Go and Rust projects in ports. They store all the dependencies and their hashes in the build recipe, not trusting the project ones. And they’re more readable. Here is jujutsu’s list of dependencies[0] and their hashes[1]. As an aside, that’s why I don’t like those packages managers. Something like Python’s numpy or lib curl, get sliced into atomic portions. [0]: https://github.com/openbsd/ports/blob/master/devel/jujutsu/crates.inc https://github.com/openbsd/ports/blob/master/devel/jujutsu/c... [1]: https://github.com/openbsd/ports/blob/master/devel/jujutsu/distinfo https://github.com/openbsd/ports/blob/master/devel/jujutsu/d...
- cxr 5mo agoECMA-262 doesn't require the use of NPM or NodeJS. (In fact, they are at odds, even 10+ years after modules were standardized in ES6.)
- suprjami 5mo agoYou do remember the xz-utils backdoor was found in Sid right? https://en.wikipedia.org/wiki/XZ_Utils_backdoor https://en.wikipedia.org/wiki/XZ_Utils_backdoor
- Dwedit 5mo agoIt would have been found in a whole lot more places if it hadn't been for that meddling Microsoft employee.