No, you cannot trust third party code without reading it first

For more than a decade I have been thundering against a lot of the bad practices that have permeated the software development industry, one such practice is to blindly trust code when using third party libraries, frameworks or packages. For about the same amount of time I have listened to all the reasons why time is money and we need to build something quickly, and we haven't got the time to do security or X, Y and Z. But alas, now such companies are beginning to pay the price, a very costly and extremely damaging price! https://unixsheikh.com/articles/no-you-cannot-trust-third-party-code-without-reading-it-first.html

Creato 3y | 11 ago 2022, 16:21:23


Accedi per aggiungere un commento

Altri post in questo gruppo

No your PHP framework isn't MVC, but don't worry, it really shouldn't be!

Most of the popular PHP frameworks postulate that they implement the model-view-controller (MVC) pattern, but it's just not true. https://unixdigest.com/articles/no-your-web-application-isnt-mvc.html

23 mag 2025, 11:40:03 | unixsheikh
Future prediction: The so-called modern web will die soon

For many years I have been advocating passionately against the so-called "modern web" because it is a poor excuse of saving money by doing so-called rapid deployment. Many web developers, front-end as

23 mag 2025, 11:40:03 | unixsheikh
Why is your open source project still hosted on GitHub?

Perhaps the younger generation don't know anything about the past "evils" of Microsoft and naively believe that Microsoft is now the good friend to open source, but the truth is that all Microsoft acq

22 mag 2025, 00:50:02 | unixsheikh
Evilness is when profit is the sole concern

When a company is small it's easy to care about the good and the evil it does, but when a company gets big, typically profit becomes the sole concern and that is when evilness takes root and starts to

9 mag 2025, 06:40:07 | unixsheikh
The reason why i don't use AI or even code completion

When I code, I don't use AI and I don't even use code completion, this post is about why not. https://unixdigest.com/articles/the-reason-why-i-dont-use-ai-or-even-code-completion.html

1 mag 2025, 01:40:05 | unixsheikh
Microsoft CEO says up to 30% of the company's code is written by AI - no surprise there

According to an article on TechCrunch Microsoft CEO says up to 30% of the company’s code is written by AI. https://unixdigest.com/articles/microsoft-ceo-says-up-to-30-percent-of-the-companys-code-is-w

1 mag 2025, 01:40:04 | unixsheikh