
The Risks of Decomposing Software Components
The New Stack Podcast
00:00
The Role of Open Source Software Repositories in Security
GitHub recently announced that they've introduced support in the NPM package manager for provenance traceability. The question you asked at the beginning, how do I know where the source is and how I can dive into it? That's how to look for problems rather than just trusting that some entry in a repo is like a database. We're working with them through a working group focused on the needs of the securing software repositories.
Transcript
Play full episode