‹ BackHN Continuity

Thread

Don't couple your Go code to GitHub

325 points · 177 comments · birdculture

  1. 0xbadcafebee · · focus · HN ↗
    Even better reason: you can later point this domain at an artifact registry. This not only gives you reliability and flexibility, it also secures your software supply chain. You don't need an SBOM or anything fancy to get started, just pull all your artifacts into a central source and improve it over time. Install an artifact registry anywhere you can run a container, use dumb static shared credentials, and start with "proxy mode". Later on you can pin or restrict versions, verify checksums, implement SSO, etc. This is going to become table stakes in the new security landscape.
    1. prasadvara · · focus · HN ↗
      You don't need an SBOM or anything fancy to get started

      -- Curious how this avoids SBOM need?

      1. 0xbadcafebee · · focus · HN ↗
        An SBOM is an inventory; you don't need to make an inventory to pull files through a proxy.
        1. prasadvara · · focus · HN ↗
          Correct, that is what confused me, how SBOM came into the picture, now got it, thanks!
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.