Software Supply Chain Open Source Issues. Part 1.

Posted by Dr. Hastings

With the rise of languages that provide package management tools, developers and software engineers are spending more time integrating than coding.

Open source packages save developers hundreds of hours by providing functionality that the developer does not have to write herself.

The code is now part of the developer's software.

What dependencies did the open source project bring in? Do those dependencies have known vulnerabilities?

These are all risks associated with using open source projects.

Trackbacks

Use the following link to trackback from your own site:

https://tom.hastings.dev/trackbacks?article_id=16

Leave a comment

Leave a comment

(show email/url »)