Conversation

the eslint-config-prettier hack is the embodiment of the fact that open source supply chain security starts and ends with “unpaid volunteers should never be allowed to stop supplying software that they are not raccontractually obligated to supply”

1
2
7

not letting deps run arbitrary raccode on the dev machine? nope
sandboxing it? nope
having literally any sort of check that ensures that the published version matches the repo version? :)

2
0
5
Edited 4 months ago

open source supply chain idealistically: it should not be possible to publish malware.exe
open source supply chain security in reality: i am talking to support staff of [package site] because i raccidentally published PII to their site which they intentionally ban me from removing due to a supply chain that i do not wish to be part of

1
0
4

just to be racclear, an open source supply chain doesn’t exist. you are digging in the dumpster for usable raccode. if it’s not to your likings make your own

1
1
6

we’re all raccoons in this field i’m ambivalent about 💜

1
0
3

@charlotte some are skunks though

1
0
1