6 ms·
I guess that’s more of a problem if you use all-encompassing frameworks, but normally the things I’m using are very small components where the CVEs either don’t
by dwroberts 1mo ago
I guess that’s more of a problem if you use all-encompassing frameworks, but normally the things I’m using are very small components where the CVEs either don’t exist or are inconsequential/unexploitable for the programs I’m building
- LtWorf 1mo agoSo you don't track them, have no way of tracking them and just hope for the best. I hope no customer of yours asks for an SBOM :D
- dwroberts 1mo agoUpdating every dependency for every kind of CVE is a brute force method for people and organisations that don’t understand the attack surface of the programs they’re producing
- LtWorf 1mo agoAnd vendoring without having any idea of what is in there and doing no monitoring is peak engineering?
- dwroberts 1mo agoWho is doing what you’re describing? The reason I can confidently freeze and offline stuff is because I’m not taking in whole frameworks, I’m selecting things carefully, and generally do end up reading at least most of the source And what ‘monitoring’ are you going to be doing besides things like CVEs?