TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

State of the Software Supply Chain 2021

15 点作者 livealight超过 3 年前

5 条评论

timw4mail超过 3 年前
&quot;Vulnerabilities are more common in popular projects.&quot; - meaning more popular projects have more known issues, which seems kind of obvious.<p>Perhaps &#x27;security by obscurity&#x27; has its parallel in &#x27;vulnerability in popularity&#x27;.<p>While not a good security tactic in general, there is something to the fact that an obscure library will be less exploited.
评论 #28539796 未加载
marcus_holmes超过 3 年前
Or, y&#x27;know, think carefully before adding a dependency to your project, and add as few dependencies as possible.
评论 #28539770 未加载
phkahler超过 3 年前
Interesting read. One thing seems to be missing, and that is any notion of participating in upstream development. In open source you don&#x27;t have to just be a consumer, you can actively participate in the development of dependencies to varying degrees. They do point to people near the edge vs on the edge as having better practices, and I&#x27;d think that&#x27;s because they at least <i>follow</i> and understand what&#x27;s going on vs just using the latest. Following and understanding seems very close to participating, though they are different.
评论 #28539923 未加载
nixpulvis超过 3 年前
With so many irrelevant advisories, I&#x27;m not sure I can take much from this report TBH. Not to mention that I disagree about MTTU, a stat that is clearly skewed toward pencil pushers.<p>The more time you spend updating dependencies, the less time you spend actually coding things. Well, unless the updates actually give you new features, which is generally not what people are looking for when running an update for some reason.
评论 #28539733 未加载
makeitrain超过 3 年前
To read this on a phone, you have to trick the content into loading by scrolling past it, then scrolling back up.