josephlord@union.place (@josephlord@union.place)
Feed is a mix of politics (left, privacy, equality, tech) and some tech (Swift and iOS mostly). He/him, (they/them if you want) BLM ✊🏿 I was @jl_hfl before the fall of the bird place.
Post
-
I wish that those surveys so often cited by InfoSec pundits that ask
Senza categoriaNo. I don’t trust third-party dependencies in general.
Define verify? The extent of verification depends in trust in third party and the project I am making dependent (risk profile, expected life etc.).
Red flags would include things like too many onwards dependencies, dependencies that I consider to be privacy risks etc.
On the other hand I have high trust in things like official Swift project packages, SQLite and substantial trust in things like the Vapor project.