• anyhow2503@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    ·
    13 hours ago

    The good news is that there already is a gold standard for supply chain security: the Go programming language.

    Lmfao

    • bright_side_@piefed.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      11 hours ago

      Competent standard lib + decentralized libs + checksum db.

      While the article is a bit theatralic, it offers important arguments.

      • anyhow2503@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        5 hours ago

        There are some good points in it, though I wouldn’t really consider go dependencies all that decentralized in practice and I don’t understand how checksum db will protect against supply chain attacks with stolen credentials, but I admit I haven’t looked into the details.

        • bright_side_@piefed.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          34 minutes ago

          Yep you’re right, tampering before transmission is still possible. I think I agree with having a strong standard lib helping that considerably. While the language of the blog is not objective, the “content” was better than expected 😊