No, you cannot trust third party code without reading it first

For more than a decade I have been thundering against a lot of the bad practices that have permeated the software development industry, one such practice is to blindly trust code when using third party libraries, frameworks or packages. For about the same amount of time I have listened to all the reasons why time is money and we need to build something quickly, and we haven't got the time to do security or X, Y and Z. But alas, now such companies are beginning to pay the price, a very costly and extremely damaging price! https://unixsheikh.com/articles/no-you-cannot-trust-third-party-code-without-reading-it-first.html

созданный 3y | 11 авг. 2022 г., 16:21:23


Войдите, чтобы добавить комментарий

Другие сообщения в этой группе

No your PHP framework isn't MVC, but don't worry, it really shouldn't be!

Most of the popular PHP frameworks postulate that they implement the model-view-controller (MVC) pattern, but it's just not true. https://unixdigest.com/articles/no-your-web-application-isnt-mvc.html

23 мая 2025 г., 11:40:03 | unixsheikh
Future prediction: The so-called modern web will die soon

For many years I have been advocating passionately against the so-called "modern web" because it is a poor excuse of saving money by doing so-called rapid deployment. Many web developers, front-end as

23 мая 2025 г., 11:40:03 | unixsheikh
Why is your open source project still hosted on GitHub?

Perhaps the younger generation don't know anything about the past "evils" of Microsoft and naively believe that Microsoft is now the good friend to open source, but the truth is that all Microsoft acq

22 мая 2025 г., 00:50:02 | unixsheikh
Evilness is when profit is the sole concern

When a company is small it's easy to care about the good and the evil it does, but when a company gets big, typically profit becomes the sole concern and that is when evilness takes root and starts to

9 мая 2025 г., 06:40:07 | unixsheikh
The reason why i don't use AI or even code completion

When I code, I don't use AI and I don't even use code completion, this post is about why not. https://unixdigest.com/articles/the-reason-why-i-dont-use-ai-or-even-code-completion.html

1 мая 2025 г., 01:40:05 | unixsheikh
Microsoft CEO says up to 30% of the company's code is written by AI - no surprise there

According to an article on TechCrunch Microsoft CEO says up to 30% of the company’s code is written by AI. https://unixdigest.com/articles/microsoft-ceo-says-up-to-30-percent-of-the-companys-code-is-w

1 мая 2025 г., 01:40:04 | unixsheikh