TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

The best free, open-source supply-chain security tool? The lockfile

5 点作者 moyer超过 3 年前

1 comment

ievans超过 3 年前
Author here. The idea for this post came about after a HN reply (<a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=28965469" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=28965469</a>) to one of my comments about the ua-parser-js issue. And the most recent trigger was a conversation with some Ruby developers about whether or not Gemfile.lock provided any security benefits (as you can see from the chart, bundler is an outlier compared to pip&#x2F;npm&#x2F;yarn). I wanted to collect the arguments for and against lockfiles and examine how widely supported the most critical features; would love feedback on the arguments as well as whether I’ve gotten the details write on which package manager supports what.