36 votes

Sandwich bill of materials

9 comments

  1. [3]
    zod000
    Link
    Requiring a sandwich bill of materials for sandwiches will likely end up with not getting many sandwiches, but this was a fun (to me) link. Thanks for sharing.

    Requiring a sandwich bill of materials for sandwiches will likely end up with not getting many sandwiches, but this was a fun (to me) link. Thanks for sharing.

    10 votes
    1. [2]
      asteroid
      Link Parent
      I laughed. I thought you might, too!

      I laughed. I thought you might, too!

      7 votes
      1. chocobean
        Link Parent
        I want to inspect these 6% of sandwiches with a lockfile This was my favourite bit:

        Post-incident analysis revealed that 94% of affected sandwiches had no lockfile and were resolving eggs to latest at assembly time.

        I want to eat inspect these 6% of sandwiches with a lockfile

        This was my favourite bit:

        CVE-2019-SPROUT: Alfalfa sprouts were found to be executing arbitrary bacteria in an unsandboxed environment. Severity: High. The vendor disputes this classification.

        7 votes
  2. [2]
    moocow1452
    Link
    Ugh, sandwich licenses. Why do I need to open up the sandwich and check third party sources so I can put Sriracha sauce on myself when I can just pay for a sandwich that has brand name Sriracha at...

    Ugh, sandwich licenses. Why do I need to open up the sandwich and check third party sources so I can put Sriracha sauce on myself when I can just pay for a sandwich that has brand name Sriracha at the proprietary shop down the road? And I know about OpenHot and Yet Another Spicy Sauce, they just don't fit my use case. /j

    5 votes
    1. pete_the_paper_boat
      Link Parent
      YASS would probably do well on brand recognition alone

      YASS would probably do well on brand recognition alone

      3 votes
  3. [2]
    HiddenTig
    Link
    Stupid things broke - I tried to compile a hotdog and it crashed despite meeting spec requirements.

    Stupid things broke - I tried to compile a hotdog and it crashed despite meeting spec requirements.

    4 votes
    1. moocow1452
      (edited )
      Link Parent
      Works on my end, try a previously unused kitchen?

      Works on my end, try a previously unused kitchen?

  4. sorkceror
    Link
    This is great, thanks for sharing!

    This is great, thanks for sharing!

    2 votes
  5. tanglisha
    Link
    I love this! SBOMs are such a great idea, but always felt hopeless to me because of dependency chains. Add that to vulnerability scanners that complain about everything right down to the language...

    I love this!

    SBOMs are such a great idea, but always felt hopeless to me because of dependency chains.

    Add that to vulnerability scanners that complain about everything right down to the language you're using and defenestration seems like the best option.