How does your company manage open-source dependencies?

https://news.ycombinator.com/item?id=33332785
by ddadon10 • 4 years ago
3 1 4 years ago

I am reading more and more about software supply chain security[1][2] and wondering how companies are managing open-source dependencies, especially big corp.

Eg:

- Can you just install any dependency without an audit?

- Does the top management takes those issues seriously?

- Do you have some horror stories to share? (outside Log4j of course)

Would love to have some insight on that, and the company size (number of employees etc)

[1]: https://slsa.dev/

[2]: https://securityscorecards.dev/

Related Stories

Loading related stories...

Source preview

news.ycombinator.com