chicken nuget
Insecure #curl packages hosted by Microsoft. They think it's fine.
Post
chicken nuget
Insecure #curl packages hosted by Microsoft. They think it's fine.
@bagder
I think I have asked you about this already, but please consider nuget prefix reservation for "Curl":
https://learn.microsoft.com/en-us/nuget/nuget-org/id-prefix-reservation
https://www.nrk.no/bokbrevet/bokbrevet-_65-hvor-blir-det-av-de-minneverdige-karakterene-i-samtidslitteraturen_-1.17797235 - kanskje to grunner, her ... det er norsk, og vi tror på "seriøs litteratur"
Tro meg, ingen kommer nevne Tengel på den DER lista ...
@bagder Yeah, this is exactly the way, how Microsoft (and btw. most of Bigtec) understand live governance.
@bagder I have a strong feeling you've already written about #Microsoft using outdated #curl version somewhere.
Am I hallucinating?
@safigo sure, I link to my previous nuget complaint in the post: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/ - but I probably did it more times as well
@bagder I think this isn't a nuget problem, but just package managers in general? For example, the central maven repository has loads of libraries that ship some ancient curl versions: https://central.sonatype.com/search?q=curl
I would assume the same for every other ecosystem as well
@bagder I might be thinking the wrong thing but can curl project upload curl packages to the chickencoop so that 'at least' some packages are from known source?
I know that's not your problem to fix, but still...
@luisfcorreia sure, in theory that could possibly be done. But to me that would feel like giving in to them and accepting this as how it needs to be so I will not participate in that.
This is a Bonfire Federated social instance for those that enjoy gnarly adventures. Whether it's shredding mountains or slaying guitars, from action sports to art.