4 ms·
And the best recommendation security teams can give - keep your SBOM strict, use min release age policy (sounds more like band-aid). That's a scary world to liv
by zihotki 4mo ago
And the best recommendation security teams can give - keep your SBOM strict, use min release age policy (sounds more like band-aid). That's a scary world to live in.
- wolfi1 4mo agoa friend of mine has a very different solution: he codes everything by hand. he says that the time you need to research to include a new package you can actually use to code the piece you need. and he for sure doesn't have the problems of transitive dependencies
- dgellow 4mo agoI assume that means he genAIs all his deps? Rather than writing by hand
- nicce 4mo agoDepending of the scenario, it can be very fine. E.g. if you just need one or two function call from the dependency. However, for some complex binary protocols it might be better to stick with libraries.
- hsbauauvhabzb 4mo agoBut now he needs to develop, test and maintain that code. Left pad is easily hand coded, react framework not so much.
- wolfi1 4mo agohis projects were GUIs for machines (HMI)
- hsbauauvhabzb 4mo agoThat’s not really my point. My point is some libraries are easily replaced and others are massive, complex and need ongoing support. By the same logic, he could avoid system dependencies by writing his own OS. But it obviously doesn’t scale. I’m all for an anti-library ethos, as long as the pros and cons are carefully considered and wheels are only reinvented when the cost/risk ratio is right.
- rcxdude 4mo agoEmbedded software already has a pretty strong culture of rarely using libraries and vendoring them if they do (for better and for worse). This kind of worm just doesn't really make sense in that kind of environment anyway.
- supernes 4mo agoThat's been happening to me more often too recently. I find that, for a growing number of simple problems, reinventing the wheel is faster and more efficient than importing a mature, fully-featured dependency.
- nicce 4mo ago> keep your SBOM strict Based on the news, seems like it is better to not include Microsoft at all in there.