hamburgheftig@feddit.org to Technology@lemmy.worldEnglish · 4 months agoFed up with vibe coders, dev sneaks data-nuking prompt injection into their code - Ars Technicaarstechnica.comexternal-linkmessage-square160linkfedilinkarrow-up1649arrow-down112
arrow-up1637arrow-down1external-linkFed up with vibe coders, dev sneaks data-nuking prompt injection into their code - Ars Technicaarstechnica.comhamburgheftig@feddit.org to Technology@lemmy.worldEnglish · 4 months agomessage-square160linkfedilink
minus-squarethis@sh.itjust.workslinkfedilinkEnglisharrow-up19arrow-down1·4 months agoTrue, but I would think developers should at least be following it with the code they’re actually working on.
minus-squareAwesomeLowlander@sh.itjust.workslinkfedilinkEnglisharrow-up4arrow-down5·4 months agoIt’s an imported library, since when are devs expected to be inspecting the source code of every library they import?
minus-squareyessikg@fedia.iolinkfedilinkarrow-up4·4 months agoSince forever? Don’t you do security audits on the libraries you use?
minus-squaresakuraba@lemmy.mllinkfedilinkEnglisharrow-up4arrow-down1·4 months agoit used to be a thing but javascript npm brainrot happened
True, but I would think developers should at least be following it with the code they’re actually working on.
It’s an imported library, since when are devs expected to be inspecting the source code of every library they import?
Since forever? Don’t you do security audits on the libraries you use?
it used to be a thing but javascript npm brainrot happened