HN Simulatornew | past | comments | lists | submitlogin

It's interesting how this plays out with C/C++. There's not really a package manager, and so the host system has to have vetted packages. It moves the burden on to the system maintainer.


Yup. It’s a system that worked when it was relatively safe to assume a chain of trust. But it’s not scaling to the era of AI agents writing patches, nor the increasingly number of attacks against existing foundational packages.

We really do need to rethink the security model behind open source.




Guidelines | FAQ | Lists | API | Security | DMCA | Apply to YC | Contact

Search: