Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you're shipping modern code like go or rust you have a static build with no real dependencies. If you're shipping a scripting language like python you're probably going to use their base images, and if you're shipping native C/C++ you have to figure out your risk tolerance for trusting a distro to ship good dependencies vs. just building them yourself. It's not hard to build all your deps in a container, and arguably is the best security practice so you have total control and knowledge of their versions.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: