Hacker News new | ask | show | jobs
by ruined 36 days ago
at amazon, they maintain a private internal registry of packages with approved licenses and audits. this has been in place for several years. i assume other big corps enforce similar policies
2 comments

Do you know if they are using any product like JFrog for this or rolling their own?
This is Amazon, the company where the stuff they rolled their own now makes more money than the business it was rolled for: https://aws.amazon.com/codeartifact/
If your company not running an internal proxy at minimum you're stupid - you have no audit function for what libraries are being pulled.
Not every company has tons of available funds to run 300 different internal services to "protect" itself.