← Back to context

Comment by zer00eyz

3 days ago

> Nobody is even keeping up with the systems we built to help us keep up. So we ship without quite knowing what we shipped, and the sloppiness follows from that.

NPM left-pad incident was a decade ago. Supply chain attacks have been a thing for longer than that (one of the first proposed SBOM's was around that time).

Source forge was shoving adware into the software from their site.

Asking an AI to write code is not worse than typing in PIP/NPM install (not to slight those tools) if you aren't going to code review either.