My Lemmy Oracle
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
codeinabox@programming.dev to Programming@programming.devEnglish · 1 day ago

Every dependency you add is a supply chain attack waiting to happen

benhoyt.com

external-link
message-square
18
fedilink
131
external-link

Every dependency you add is a supply chain attack waiting to happen

benhoyt.com

codeinabox@programming.dev to Programming@programming.devEnglish · 1 day ago
message-square
18
fedilink
Dependencies are a huge supply chain security risk; the more of them you have, and the more often you update, the bigger the attack surface.
  • MonkderVierte@lemmy.zip
    link
    fedilink
    arrow-up
    4
    ·
    12 hours ago

    Soo, how do i build Rust packages without Cargo?

    • BB_C@programming.dev
      link
      fedilink
      arrow-up
      1
      ·
      55 minutes ago

      Why do you think cargo is a problem?

    • TehPers@beehaw.org
      link
      fedilink
      English
      arrow-up
      4
      ·
      8 hours ago

      You can run rustc directly! You just need to pass about 30 different parameters to it as well as a list of all the dependencies you use and…

      Look, it works for small projects.

      • MonkderVierte@lemmy.zip
        link
        fedilink
        arrow-up
        1
        ·
        8 hours ago

        So i could theoretically script a wrapper?

        • TehPers@beehaw.org
          link
          fedilink
          English
          arrow-up
          3
          ·
          8 hours ago

          I don’t see why not. Cargo is fundamentally just a fancy wrapper around rustc, anyway. Sure, it’s a really fancy wrapper that does a lot of stuff but it’s entirely possible to just call rustc yourself.

    • thedeadwalking4242@lemmy.world
      link
      fedilink
      arrow-up
      3
      ·
      11 hours ago

Programming@programming.dev

programming@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

Welcome to the main community in programming.dev! Feel free to post anything relating to programming here!

Cross posting is strongly encouraged in the instance. If you feel your post or another person’s post makes sense in another community cross post into it.

Hope you enjoy the instance!

Rules

Rules

  • Follow the programming.dev instance rules
  • Keep content related to programming in some way
  • If you’re posting long videos try to add in some form of tldr for those who don’t want to watch videos

Wormhole

Follow the wormhole through a path of communities [email protected]



Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 199 users / day
  • 1.78K users / week
  • 3.85K users / month
  • 8.64K users / 6 months
  • 1 local subscriber
  • 26.4K subscribers
  • 3.03K Posts
  • 42.4K Comments
  • Modlog
  • mods:
  • snowe@programming.dev
  • Ategon@programming.dev
  • UlrikHD@programming.dev
  • bugsmith@programming.dev
  • Spyro@programming.dev
  • BE: 0.19.5
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org