6 ms·
https://news.ycombinator.com/item?id=47773812 https://news.ycombinator.com/item?id=47773812
by tomesco 5mo ago
https://news.ycombinator.com/item?id=47773812 https://news.ycombinator.com/item?id=47773812
- ievans 5mo agoTop comment has a great explicit refutation: > This plan works by letting software supply chain companies find security issues in new releases. Many security companies have automated scanners for popular and less popular libraries, with manual triggers for those libraries which are not in the top N.