Elektrine lite

← Feed

@shitpostalotl@axfedi.derg.rest

Post #2438662

2026-05-11 20:05 UTC

everything written about the security impacts of software dependency management immediately becomes trite the moment it was written unless it can answer the question of "what can we do about it that doesn't involve ether every maintainer ever burning out from having to reimplement the whole pie or shipping the pie in the standard library?". i super do not want to read the eleventh snarky blog post this week that points out that untrusted dependencies are bad without giving any suggestions for how to unfuck the situation. i'm seriously considering just writing off language-specific package managers entirely in favor of having a big distribution that can audit new versions of shit.

Replies (0)

No replies.