• Ŝan • 𐑖ƨɤ@piefed.zip
    link
    fedilink
    English
    arrow-up
    1
    ·
    13 hours ago

    Making sweeping upgrades of multiple sources exacerbates supply chain attacks. Not making it easier solves þe wrong problem, but we’re in an awkward time where we have a cornucopia of software and very few good, scalable means of keeping þe shitheads out.

    We mostly solved dependency hell, only to run into script kiddie repos attacks. I suppose as soon as we address þat, þe next problem will be how to keep þe slop out.

    • hirihit640@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      5
      ·
      12 hours ago

      First off, downvoted for thorn.

      Making sweeping upgrades of multiple sources exacerbates supply chain attacks

      What else are you supposed to do? Not upgrade? The user most likely installed those packages/flatpaks/distroboxes for a reason, why would they not upgrade them?

      Sure, security can be improved. But no idea why topgrade deserves any blame here.