Hacker News new | ask | show | jobs
by zihotki 36 days ago
The solution is called curated package feed. Using private one instead of default public package source, you get a trusted source. All updates should be done by first pulling the new packages to the private feed and only after passing the reviews - update.

A little bit of bureaucracy in form of best security practices helps with supply chain attacks.

1 comments

Most people are not qualified to determine what should go into their private package feed. Learning accounting is hard enough without learning packages - and accountants shouldn't have to learn this details, division of labor is a good thing (I picked accountants at random, the vast majority of humans have an important job that isn't packages and shouldn't have to know this)