logoalt Hacker News

Ferret7446last Thursday at 2:59 AM1 replyview on HN

I'd suggest you submodule in dependencies rather than curl. Supply chain attacks and version incompatibilities both happen and suck


Replies

susamlast Thursday at 3:18 AM

> I'd suggest you submodule in dependencies rather than curl. Supply chain attacks and version incompatibilities both happen and suck

What kind of supply chain attack or version incompatibility would affect

  curl -sSL https://github.com/edicl/hunchentoot/archive/v1.3.1.tar.gz | tar -xz
but not

  git submodule add https://github.com/edicl/hunchentoot.git && cd hunchentoot/ && git checkout v1.3.1

?
show 1 reply