Lemmy.World
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
codeinabox@programming.dev to Programming@programming.devEnglish · 1 day ago

Every dependency you add is a supply chain attack waiting to happen

benhoyt.com

external-link
message-square
12
link
fedilink
  • cross-posted to:
  • [email protected]
123
external-link

Every dependency you add is a supply chain attack waiting to happen

benhoyt.com

codeinabox@programming.dev to Programming@programming.devEnglish · 1 day ago
message-square
12
link
fedilink
  • cross-posted to:
  • [email protected]
Dependencies are a huge supply chain security risk; the more of them you have, and the more often you update, the bigger the attack surface.
  • Eager Eagle
    link
    fedilink
    English
    arrow-up
    39
    ·
    1 day ago

    You should probably turn off Dependabot

    Nonsense, most of these supply chain attacks are detected and have their problematic versions pulled within a few hours. Just set a cooldown period for dependabot.

    • Slyke@programming.dev
      link
      fedilink
      arrow-up
      3
      ·
      10 hours ago

      The discovered ones anyway.

    • corsicanguppy@lemmy.ca
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 day ago

      Newer is not often better.

Programming@programming.dev

programming@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

Welcome to the main community in programming.dev! Feel free to post anything relating to programming here!

Cross posting is strongly encouraged in the instance. If you feel your post or another person’s post makes sense in another community cross post into it.

Hope you enjoy the instance!

Rules

Rules

  • Follow the programming.dev instance rules
  • Keep content related to programming in some way
  • If you’re posting long videos try to add in some form of tldr for those who don’t want to watch videos

Wormhole

Follow the wormhole through a path of communities [email protected]



Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 288 users / day
  • 1.93K users / week
  • 3.78K users / month
  • 8.52K users / 6 months
  • 6.98K local subscribers
  • 26.4K subscribers
  • 3K Posts
  • 42.1K Comments
  • Modlog
  • mods:
  • Ategon@programming.dev
  • snowe@programming.dev
  • UlrikHD@programming.dev
  • bugsmith@programming.dev
  • Spyro@programming.dev
  • UI: 0.19.17-6-gd2cd87b1
  • BE: 0.19.17-7-gf48cd284c
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org