| ▲ | susam 3 days ago | ||||||||||||||||
> I'd suggest you submodule in dependencies rather than curl. Supply chain attacks and version incompatibilities both happen and suck What kind of supply chain attack or version incompatibility would affect
but not | |||||||||||||||||
| ▲ | Ferret7446 2 days ago | parent [-] | ||||||||||||||||
Submodules are pinned by commit hash. It prevents an attacker from replacing a release. | |||||||||||||||||
| |||||||||||||||||