| ▲ | neoromantique 9 hours ago | ||||||||||||||||
I'm sorry, but I don't agree. Current dependency hell that is modern development, just how wide the openings are for supply chain attacks and seemingly every other week we get a new RCE. I'd rather 100 loosely coupled scripts peer reviewed by a half a dozen of LLM agents. | |||||||||||||||||
| ▲ | pca006132 8 hours ago | parent [-] | ||||||||||||||||
But this doesn't solve dependency hell. If the functionalities were loosely coupled, you can already vendor the code in and manually review them. If they are not, say it is a db, you still have to depend on that? Or maybe you can use AI to vendor dependencies, review existing dependencies and updates. Never tried that, maybe that is better than the current approach, which is just trusting the upstream most of the time until something breaks. | |||||||||||||||||
| |||||||||||||||||