TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

The many (many) ways I've backdoored your dependencies and other supply chain at

19 点作者 severine大约 1 年前

5 条评论

OJFord大约 1 年前
So what do we do? I really think something like Firejail must be the way to go, but it&#x27;s absolutely not ready for user-friendly prime time. And what do you do on macOS, or for every little tool like `ls` (where I want say filesystem access but not network).<p>It all seems a bit hopeless, I refuse to believe anyone who claims to audit everything and every update - and would they have caught xz&#x27;s backdoor anyway?
评论 #40174556 未加载
评论 #40168418 未加载
boesboes大约 1 年前
Most of these point come down to: don&#x27;t trust random shit from the internet and don&#x27;t blindly pull it into your projects&#x2F;env.
评论 #40168361 未加载
评论 #40168287 未加载
评论 #40168239 未加载
评论 #40168243 未加载
karma_pharmer大约 1 年前
Enable JavaScript and cookies to continue
mtmail大约 1 年前
&quot;By now, you may have guessed that I didn&#x27;t have literally backdoored your dependencies, but someone else may have, or will.&quot;
评论 #40169326 未加载
eureka-belief大约 1 年前
Broken link
评论 #40168096 未加载