Settings

Theme

Dependency Tracking Is Hard

daniel.haxx.se

13 points by riffraff 7 hours ago · 3 comments

Reader

dhruv3006 2 hours ago

GitHub lists one dependent repo for curl and that too is a mistake.

nacozarina 3 hours ago

it’s cache-invalidation in different clothes, it will always be a pain in the tucus

direwolf20 3 hours ago

Dependency tracking for security is like any other security work: the purpose is to create the perception of security, not actual security. You can sell the perception of security. You can't sell actual security. That's why every other corporation has a WAF now that doesn't block attacks but does block legitimate traffic, and how Cloudflare managed to create the world's biggest MITM without a single crime.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection