My code depends on a library that makes liberal use of patching (replacing text in source code) for its own dependencies. I feel this is bad form, because, for example, that dependency may now conflict irreconcilably with another dependency of mine.

Am I right in thinking patching code is bad form?

  • fruitycoder@sh.itjust.works
    link
    fedilink
    arrow-up
    1
    ·
    2 days ago

    Bad form. Breaks SLSA some. Breaks some CVE tracking tools too.

    If the patch introduces a vulnerabilty or breaking issue how would it be tracked?