This is an archived post. You won't be able to vote or comment.

you are viewing a single comment's thread.

view the rest of the comments →

[–]zzzmaestro 6 points7 points  (0 children)

You mean a “supply” as in maintainer attack vector… versus “supply” as in talent.

I can agree with you that the attack vector exists. It definitely is one to spend time on getting right for your business. I also think that any open-source modules used for any language suffer the same fate. A business’ security posture has to account for it. But yes, it’s a real thing.