Hacker News new | ask | show | jobs
by tex0 1388 days ago
I disagree. All the examples you mention are part of the software supply chain.

To me it doesn't matter if code comes in through a vendor, a dependency or is written in house.

It's all well within the responsibility of the organization owning and deploying the artifacts.