Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What if there were some way to specify a difficult to forge checksum for your dependencies?


They could call it an SBOM...


I think tedunangst is referring to https://man.openbsd.org/signify.1


Even simpler than that, something like bsd ports distfiles checksums, or go.sum, or whatever. If you depend on something, you should know what that something is, and you should have some measure of it in your code/project.


Like a SBOM


Like a commit hash?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: