Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
west0n
on March 30, 2024
|
parent
|
context
|
favorite
| on:
Backdoor in upstream xz/liblzma leading to SSH ser...
It seems that to counter this type of supply chain attack, the best practices for managing software dependencies are to pin the version numbers of dependencies instead of using `latest`, and to use static linking instead of dynamic linking.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: