logoalt Hacker News

SkyPuncheryesterday at 1:39 PM1 replyview on HN

But, pinning has prevented most of the recent supply chain attacks.

As long as you don't update your pins during an active supply chain attack, the risk surface is rather low.


Replies

habineroyesterday at 9:16 PM

The flip side of that is now you're running old software and CVEs get published all the time. Threat actors actively scan the internet looking for software that's vulnerable to new CVEs.