Importance of Source Code Management

The article below highlights a very interesting risk associated with Source Code Management.

https://www.theregister.com/2022/03/18/protestware_javascript_node_ipc/?td=rt-3a

This is not the first time that a developer has?purposely made changes?to code which have caused issues with either service availability and/or data integrity.

What stands these 2 issues apart from the supply-chain vulnerabilities such as the recent?SolarWinds issue, is that rather than a 3rd?party compromising the source code used in a product, in the above two cases, it is the code owner themselves who have purposely made destructive changes?

Key to my message is the criticality of source code management, coupled with testing (eg. auto-regression testing as part of CI/CD).?It speaks strongly to the importance of careful analysis of code/package inheritance, especially when working with opensource projects and code.

Fun Reading ...

If you’ve not read the following article … when you’ve a few minutes and a nice fresh coffee – I’d?strongly?(like my cheeky use of the HTML <strong> tag there????) recommend reading?https://users.ece.cmu.edu/~ganger/712.fall02/papers/p761-thompson.pdf

Written in 1984, it resonates as strongly today as it did when I first read it in the late 80’s / early 90’s !!!

Original Post

This post was originally authored on my personal site, you can see it at https://blog.dtc.ninja/wp/2022/03/18/importance-of-source-code-management/

Sadly not the first example of this. I recall an example some time ago of a source code owner of some considerably well adopted libraries pulling access, causing massive challenges. Great article my friend, definitely more than simple food for thought!

回复

要查看或添加评论,请登录

Andrew Barnes的更多文章

  • What a Journey

    What a Journey

    Today has been a Good Day - I got to met some of the team I have worked with for years. Specifically they joined me as…

  • Darkness Into Light 2023

    Darkness Into Light 2023

    Today I joined my first "the "Darkness Into Light" walk, in support of Suicide Awareness. If you will indulge me, I…

    9 条评论
  • Committed to a Cause

    Committed to a Cause

    New understanding of the Mayan calendar has got me thinking about what it means to take a long-term view , and the…

    1 条评论
  • World Diabetes Day 2022

    World Diabetes Day 2022

    Today is World Diabetes Day! (14/Nov/2022) Both my daughter Alana and I are Type 1 Diabetics, Alana diagnosed in 2013…

    4 条评论
  • OpenSSL Security Advisories – CVE-2022-3602 and CVE-2022-3786

    OpenSSL Security Advisories – CVE-2022-3602 and CVE-2022-3786

    OpenSSL have just published 2 HIGH security advisories — previously pre-announced as a single CRITICAL advisory The…

    5 条评论
  • Staying Silent

    Staying Silent

    Yesterday I became aware of a story in the news which has shaken me to my core WARNING – Sensitive Topic Below PLEASE…

    4 条评论
  • Unexpectations

    Unexpectations

    Type 1 #Diabetes is an interesting beast. Interesting as a Type 1 yourself, but being parent to a Type 1 is a different…

    6 条评论
  • Dell Technologies World - Day 3

    Dell Technologies World - Day 3

    Day 3 of Dell Technologies World. It might have been my last day, but that didn’t make it any less awesome! Learning…

    12 条评论
  • Dell Technologies World - Day 2

    Dell Technologies World - Day 2

    Early starts and late nights might become a theme for the next couple of days at Dell Technologies World! Lost in the…

    2 条评论
  • Dell Technologies World 2022 - Day 1

    Dell Technologies World 2022 - Day 1

    This is my first ever visit to Dell Technologies World (DTW), and my first vendor event since before COVID. And, I'm…

    2 条评论

社区洞察

其他会员也浏览了