Elektrine lite

← Feed

@gonzo_askold@mastodon.social

Post #3138562

2025-08-28 04:22 UTC

@joshbressers@infosec.exchange being dependent on russian code is a security risk, you can't guarantee freedom of expression in a country known to disappear people with wrong political positions. if everybody does that it doesn't mean that it's safe and "popularity" of single person maintained open source solutions does not in any way hint at their security characteristics if one person can maintain that code why just not embedded it directly in your repository? be a man, manage your f*cking js modules

Replies (1)

  • @Natanox@chaos.social 2025-08-28 07:41

    @gonzo_askold@mastodon.social @joshbressers@infosec.exchange Unfortunately by now the same applies to projects maintained from the US (and obviously also China). Even though people are usually still traceable im the first, they can't work on anything from within Prison or ICE detention. Don't think country-based scrutiny of trust in developers works anymore these days. I agree that you should properly manage your god damn dependencies, of course.

    Open ##3138563