Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This drove me crazy at previous companies where our build system dependencies were specified with wildcards so they would just auto pull in the latest version whenever you built the project. Not only are there security issues with that, as seen here, but it destroys your ability to have deterministic builds; every time you build the project it might be building against a different set of dependencies. You lose the ability to even compare builds against each other, because even though the builds are for the same exact project code, the dependency binaries might be different, and so the two builds could run differently.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: