@jarredsumner you are being challenged
by @YoavCodes
blocked me for calling out his shenanigan's
of riding the bun hate wave
electrobun is riskier to use, from an author that acts on a whim and cancel a project like this
he had his 15 min of fame
https://t.co/kjmjpDwnUJ
@YoavCodes@nikolas_beckel I dare you to decouple bun already. less talking more doing.
all it will do is motivate bun to make their own electrobun.
last project that messed with bun got refactored out.
and no one even remember zip anymore.
@YoavCodes@jarredsumner I think bun people always read the code, there are thousands of PR that never get merged because no one got the time to review
also the code is open source millions of people can review it
The question is do real people still want to review code.
open source exists for a reason
@AndaristRake@boshen_c I am not saying don't trust github
we have to trust them a little, npm a little
the security scanners a little,
the people that audit a little,
and the package manager a little
with isolating and distributed trust
the overall trust level is greater than it sum
@boshen_c if one to compromise your ci env and publish a bad package, the human approval process becomes
the 2FA of the publishing.
for this to work, I think both consumers and package providers should have a delay. manual approval is good, but even that can be compromised.
@boshen_c it is called friction based continuous delivery
it does not prevent supply chain attack but
it introduce a delay at the source, instead of only the consumer side(package managers)
giving time for security scans and audit a chance to detect or review unintended publishing
@rough__sea stop calling it JavaScript
and just call it JS
JS is not even Java or a script of java
one or two letters names for programming languages works fine
C, C#, GO
case closed.
@grafana guys I think the attacker also made your repository public
I am sorry you got your open source project leaked like that
and I hope you recover fast from this.
https://t.co/VHzAwMMnVc
@mil000 I cancelled my netflix subscription and when I got back a year later, all my movies and tv shows are not deleted, sometimes some movies are gone but the majority stay.
we talking petabytes of movies
riverside needs to learn a lesson from netflix