mac
link
fedilink
1471Y

I thought it was poking fun at the tutorial saying instead of learning to code, import a library from someone who knows how to code.

@WolfLink@lemmy.ml
cake
link
fedilink
51Y

That is a large part of coding

Works as well.

billwashere
link
fedilink
English
71Y

Which is funny because when I first started my CS degree in the late 80s (get off my lawn) we used to make fun of the beginning Java classes because it seems 90% of coding was to import the right library.

That’s what libraries are for. I’m no security expert and the sensible thing to do is using a library instead of taking a class.

@bort@sopuli.xyz
link
fedilink
25
edit-2
1Y

I’m no security expert and the sensible thing to do is using a library instead of taking a class.

Counterpoint: “not knowing your libraries” + “blind trust in the maintainer” will give you stuff like this: https://bitbucket.org/snakeyaml/snakeyaml/issues/561/cve-2022-1471-vulnerability-in

(the thread itself is worth a read. But also very impressive is the list of big players who fell for exactly this mentality)

Love the part where he claims that if your users are authenticated, it’s not untrusted input. I mean, surely you trust all of your users to run any code on your server, right?

Jesus that was one hell of a thread

I dont want to see the words “low quality tooling” ever again.

Impressive and unsurprising. As soon as you start getting complex libraries with multiple dependencies it becomes nearly impossible to review everything. At one time I had an interest in contributing to some AI libraries, but they’re a mess as soon as you go looking for points of improvement.

Create a post

Post funny things about programming here! (Or just rant about your favourite programming language.)

Rules:

  • Posts must be relevant to programming, programmers, or computer science.
  • No NSFW content.
  • Jokes must be in good taste. No hate speech, bigotry, etc.
  • 1 user online
  • 18 users / day
  • 117 users / week
  • 455 users / month
  • 2.2K users / 6 months
  • 1 subscriber
  • 1.69K Posts
  • 37.2K Comments
  • Modlog