logoalt Hacker News

sscaryterrytoday at 9:35 AM2 repliesview on HN

> dependencies such as Rubygems are and will always be part of your app's Trusted Computing Base

This mindset is changing, in the npm ecosystem, managing and updating dependencies have become somewhat of a gamble. It is no longer if, its when you are compromised.


Replies

jbverschoortoday at 10:25 AM

Gems/packages should explicitly declare what kind of features they need/want (file, net, deserialization, execute)

And when the sig. changes, you should get a warning

Very similar to the iOS entitlements

_joeltoday at 10:07 AM

Checksumming the dependencies in the Gemfile may help. https://blog.rubygems.org/2024/12/19/bundler-v2-6.html

show 1 reply