Changelog Master Feed cover image

Securing the open source supply chain (Changelog Interviews #482)

Changelog Master Feed

00:00

Using Dependencies in a DevOps Environment

The average drovoscript application has 79 other transitive dependencies. Google is an example of a company that vets its open source code before releasing it to the public. If you don't fully understand every single line of yourdependencies, there's a small chance they could be used for malicious purposes. The most impracticable position would be to read every line of code and not use anything we've veted ourselves.

Play episode from 07:45
Transcript

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app