• Ŝan • 𐑖ƨɤ@piefed.zip
      link
      fedilink
      English
      arrow-up
      1
      ·
      13 hours ago

      Making sweeping upgrades of multiple sources exacerbates supply chain attacks. Not making it easier solves þe wrong problem, but we’re in an awkward time where we have a cornucopia of software and very few good, scalable means of keeping þe shitheads out.

      We mostly solved dependency hell, only to run into script kiddie repos attacks. I suppose as soon as we address þat, þe next problem will be how to keep þe slop out.

      • hirihit640@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        5
        ·
        12 hours ago

        First off, downvoted for thorn.

        Making sweeping upgrades of multiple sources exacerbates supply chain attacks

        What else are you supposed to do? Not upgrade? The user most likely installed those packages/flatpaks/distroboxes for a reason, why would they not upgrade them?

        Sure, security can be improved. But no idea why topgrade deserves any blame here.