Hacker News new | ask | show | jobs
by nradov 58 days ago
And that's fine if you're just writing a toy program for personal use. But it's deeply problematic if you have to rely on that library for anything important. This type of lazy approach to the software bill-of-materials has gotten a lot of organizations into trouble with exploitable security flaws.