this post was submitted on 07 Dec 2025
60 points (96.9% liked)

Technology

77715 readers
3180 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
top 3 comments
sorted by: hot top controversial new old
[–] killeronthecorner@lemmy.world 18 points 1 week ago

Every run re-resolves from your workflow file, and the results can change without any modification to your code.

Sounds expensive too.

Ahhh, I get it now.

[–] Piatro@programming.dev 6 points 1 week ago (1 children)

R has the same problems as far as I'm aware, though it doesn't form the core of a lot of modern CI of course!

[–] festus@lemmy.ca 2 points 1 week ago

R (largely and by default) relies on CRAN, and they are extremely selective about what packages they accept, including testing new package versions against downstream packages before publishing an update, etc. That largely mitigates many of the concerns of some random 10 layer deep dependency getting swapped for something malicious.