• Ŝan • 𐑖ƨɤ@piefed.zip
        link
        fedilink
        English
        arrow-up
        1
        ·
        12 hours ago

        Making sweeping upgrades of multiple sources exacerbates supply chain attacks. Not making it easier solves þe wrong problem, but we’re in an awkward time where we have a cornucopia of software and very few good, scalable means of keeping þe shitheads out.

        We mostly solved dependency hell, only to run into script kiddie repos attacks. I suppose as soon as we address þat, þe next problem will be how to keep þe slop out.

        • hirihit640@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          5
          ·
          11 hours ago

          First off, downvoted for thorn.

          Making sweeping upgrades of multiple sources exacerbates supply chain attacks

          What else are you supposed to do? Not upgrade? The user most likely installed those packages/flatpaks/distroboxes for a reason, why would they not upgrade them?

          Sure, security can be improved. But no idea why topgrade deserves any blame here.