Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Fundamentally, the fix isn't technical; it's social / structural.

Companies either hold themselves accountable for signing off on the dependencies they use, hold the repos accountable for signing off the dependencies, or keep doing what we've been doing.

The third option is amortized cheapest.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: