And to be clear, this is not to say that dependency security efforts are not important.
But it's important to understand that this is like car vs. plane safety; planes (dependencies) *look* really scary, but the actual thing that's likely to kill you is a car (rolling your own).
That doesn't mean that improving plane (dependency) safety doesn't matter, but it's a background process by people whose job this is, not some acute crisis that you need to deal with yourself.
(For completeness' sake: this is in the JS ecosystem. It's difficult to compare this to other ecosystems, because many ecosystems don't *have* a meaningful set of single-purpose libraries, and them being single-purpose is an important factor affecting security.)
Regarding "supply chain security" with dependencies: as a professional dependency auditor I can tell you that malicious dependencies are extremely rare... and what's far more common is security issues in utilities that large dependencies insisted on reimplementing despite safe off-the-shelf options being available.
If your takeaway from dependency security stuff is "avoid dependencies", then that is absolutely the wrong takeaway.
On the subject of Kiwifarms as a "necessary evil".
The insane notion that KF is "a necessary evil" as a source of information needs to die already.
90% of what they say is total fabrication or deformation of facts. They just use a minority of real facts to anchor all that bullshit in the truth.
Also, regardless of the accuracy of the facts they state, you HAVE to remember their entire mission statement.
Their primary goal is harassment.
They take joy in making people utterly miserable and scared. They want to invade their private lives AND ruin them if possible.
SO WHY, UNLESS YOU'RE A COMPLETE DICKHEAD, WOULD YOU WANT TO CONTRIBUTE TO THAT BY GIVING THE WEBSITE ANY SORT OF LEGITIMACY?!
Was really heartened to see approx 3,000 people turn out for trans & intersex pride Dublin today. The national gender service provides the worst trans healthcare in Europe with a decade long waiting list and dehumanising abusive and traumatizing assessments. The NGS needs to be abolished and replaced with informed consent primary healthcare in the community now! Get your psychiatry out of our sex lives! My body my choice! #Trans #Pride #MastoDaoine
Hey remember that one time I was like 'hey some admins have been in meetings with facebook and they're coming to fedi' and one dude got so mad at me talking shit about FB and 'spreading rumours' that he blocked our entire instance, then this other dude gave us shit about defederating him with a week notice while applauding the first dude for standing up for FB, then the first dude decided to block FB after all and the second dude had nothing to say about that
Must be nice being a dude
This made me laugh so hard…
https://abc7news.com/san-francisco-driverless-car-cones-sf-robotaxi-waymo-cruise/13474991/
Racism, the "there are two wolves" meme
Since I've been seeing it pop up a bunch again this week in various forms, have a reminder that the "inside you there are two wolves" meme has a racist, anti-Indigenous origin: https://apihtawikosisan.com/2012/02/check-the-tag-on-that-indian-story/
I'm not personally sure what version to make instead, but I'm also not someone who can reclaim it.
In the process of moving to @joepie91. This account will stay active for the foreseeable future! But please also follow the other one.
Technical debt collector and general hype-hater. Early 30s, non-binary, ND, poly, relationship anarchist, generally queer.
- No alt text (request) = no boost.
- Boosts OK for all boostable posts.
- DMs are open.
- Flirting welcome, but be explicit if you want something out of it!
- The devil doesn't need an advocate; no combative arguing in my mentions.
Sometimes horny on main (behind CW), very much into kink (bondage, freeuse, CNC, and other stuff), and believe it or not, very much a submissive bottom :p
My spoons are limited, so I may not always have the energy to respond to messages.
Strong views about abolishing oppression, hierarchy, agency, and self-governance - but I also trust people by default and give them room to grow, unless they give me reason not to. That all also applies to technology and how it's built.