https://www.solidot.org/story?sid=64445类似 npm、PyPI 和 RubyGems 的包管理器的流行会否使软件供应链攻击更容易发生?
@sd 其实我也有这种固有印象
不过更多的是对于「不开源=不安全」的感觉
我现在尽可能做到开源软件,能编译不下二进制,编译前看一遍源码,至少源码搜索一遍 http 关键字防止上传信息
@lemon 看一遍源码不是一般人能做到的 orz 搜索关键字是个好提议耶~
@sd 有没有自动审查软件,如果只是找关键字的话
不过话又说回来,又去依赖自动装置靠谱程度又降低了
编译前看一遍源码不切实际啊…https://wiki.c2.com/?TheKenThompsonHack@lemon @sd
CleverLibre Social is an inclusive social instance for open discussion, learning, and community. All cultures welcome. Hate speech and harassment strictly forbidden.