Olaf Schlüter
Apr 12, 2024

The short-term moral of the story is to treat external FOSS dependencies like internal dependencies - fetch a certain state of the dependency and fork it into your internal repository. We do this a lot here with FOSS dependencies that do not appear to be properly maintained. And a one-person-project is never properly maintained.

Bad thing is we do not catch transient dependencies with this not-properly-maintained property that way.

The incident stresses the importance to look at and verify the state of each external dependency you use in your software, including transient dependencies.

Sign up to discover human stories that deepen your understanding of the world.

Free

Distraction-free reading. No ads.

Organize your knowledge with lists and highlights.

Tell your story. Find your audience.

Membership

Read member-only stories

Support writers you read most

Earn money for your writing

Listen to audio narrations

Read offline with the Medium app

Olaf Schlüter
Olaf Schlüter

Written by Olaf Schlüter

IT security specialist, Physicist by education, believing in God as for the exceptional harmony of the laws of nature to create and support life.

Responses (1)

Write a response