Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So you don't track them, have no way of tracking them and just hope for the best. I hope no customer of yours asks for an SBOM :D


Updating every dependency for every kind of CVE is a brute force method for people and organisations that don’t understand the attack surface of the programs they’re producing


And vendoring without having any idea of what is in there and doing no monitoring is peak engineering?


Who is doing what you’re describing? The reason I can confidently freeze and offline stuff is because I’m not taking in whole frameworks, I’m selecting things carefully, and generally do end up reading at least most of the source

And what ‘monitoring’ are you going to be doing besides things like CVEs?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: