logoalt Hacker News

tptacekyesterday at 9:36 PM3 repliesview on HN

Reads kind of sales-pitchy. Every day we see another actively exploited Linux LPE; have you thought about your SBOM today?


Replies

ohneiyesterday at 10:25 PM

I like nix and its approach but if I'm being honest I think its also getting easier to be sloppy about dependencies and ask AI to find any dependencies that might be missing from the cleanly installed packaging metadata. There's maybe a paradox for developers in that we can try to drop structure and brute force scan first intensively enough to catch anything likely to get caught or we can ask AI to finally apply all the rigorous methods we decided were too expensive for routine software and probably have minimally more things to run with each release.

ronefyesterday at 9:52 PM

I feel we should definitely be digging way beyond the SBOM... but also wondering if the forecasting in the general ecosystem is on point or not.

show 1 reply
tremonyesterday at 10:27 PM

Are you offering an easy fix for that "Linux" line on your SBOM?

show 2 replies