Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Every place I ever worked at made sure to curate the dependencies for their main projects. Heck, in some cases that was even necessary for certifications. Web dev might be a wild west, but as soon as your software is installed on prem by hundreds or thousands of paying customers the stakes change.


Curating dependencies won't prevent all supply chain attacks though




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: