nik9000@programming.devtoRust Programming@lemmy.ml•Rust has a HUGE supply chain security problem | Sylvain Kerkour | July 2, 2024
3·
4 months agoYeah! Like that!
Yeah! Like that!
I dunno about stdx as a solution. It’s just not a big enough list.
At work we build a big java thing and we:
It’s still not enough. But it helps.
Maybe a web of trust for audited dependencies would help. This version of this repo under this hash. I could see stdx stuff being covered by the rust core folks and I’m sure some folks would pay for bigger webs. We pay employees to audit dependencies. Sharing that cost via a trusted third party or foundation or something feels eminently corporate. Maybe even possible.
Do folks still use logstash here? Filebeat and ES gets you pretty far. I’ve never been deep in ops land though.
I feel lucky to have avoided this so far. It’s really not like this on my team. I write a fair bit of code and review a ton of code.