• who@feddit.org
    link
    fedilink
    English
    arrow-up
    4
    ·
    edit-2
    4 days ago

    And it’s not just web development.

    This mindset has been spreading for… probably decades. Nowadays, it is even pushed by certain popular programming languages, by including a toolchain that makes it as easy as possible to pull in third-party dependencies while offering a standard library so minimal that a developer is strongly encouraged to rely on said dependencies.

    This inevitably leads to a world where software supply chain attacks have massive reach and high chances of success. And threat actors take advantage of it, of course.