3 ms·
It's interesting how this plays out with C/C++. There's not really a package manager, and so the host system has to have vetted packages. It moves the burden on
by leecommamichael 1mo ago
It's interesting how this plays out with C/C++. There's not really a package manager, and so the host system has to have vetted packages. It moves the burden on to the system maintainer.
- hnlmorg 1mo agoYup. It’s a system that worked when it was relatively safe to assume a chain of trust. But it’s not scaling to the era of AI agents writing patches, nor the increasingly number of attacks against existing foundational packages. We really do need to rethink the security model behind open source.