!bxVOQwsVoHhZcmNDGw:nixos.org

Nix + dotnet

120 Members
23 Servers

Load older messages


SenderMessageTime
19 Dec 2024
@6pak:matrix.org6pakimage.png
Download image.png
12:20:18
@6pak:matrix.org6pak;p12:20:22
@gggkiller:matrix.orgGGGowell, guess they lied then12:20:55
@gggkiller:matrix.orgGGGsmh my head12:21:03
@6pak:matrix.org6pakthe same can happen randomly without switching the source order if the first one is slow enough12:21:03
@6pak:matrix.org6pak * the same can happen randomly without switching the source order if the first request is slow enough12:21:10
@6pak:matrix.org6pakthis is so cursed12:21:47
@6pak:matrix.org6pakPackageReference should have a required Source property, change my mind12:23:00
@gggkiller:matrix.orgGGGI don't think it should matter honestly, unless if we're dealing with adversary sources or something12:23:53
@6pak:matrix.org6paknuget.org is an adversary source12:24:27
@6pak:matrix.org6pakanyone can upload there12:24:31
@6pak:matrix.org6pakand if you rely on a internal package thats not on nuget.org12:24:40
@6pak:matrix.org6pakanyone can claim the package id there12:24:46
@6pak:matrix.org6pakand you will just restore that instead if you dont have package source mappings setup12:25:03
@gggkiller:matrix.orgGGGfair12:25:12
@6pak:matrix.org6pakcustom sources without mapping is a big security risk12:25:17
@6pak:matrix.org6pakand shouldn't be allowed imo12:25:20
@6pak:matrix.org6paklike at all12:25:27
@gggkiller:matrix.orgGGGI guess that's the point of having nuget lockfiles12:25:36
@gggkiller:matrix.orgGGGif they didn't suck so much12:25:39
@gggkiller:matrix.orgGGG* if only they didn't suck so much12:25:46
@6pak:matrix.org6paknot really12:25:51
@6pak:matrix.org6paksomeone can upload a newer version on nuget.org12:25:59
@6pak:matrix.org6pakand just wait for you to click upgrade in VS ui12:26:05
@6pak:matrix.org6pakwithout realizing you are switching sources12:26:09
@6pak:matrix.org6paklockfile doesn't specify the source12:26:18
@6pak:matrix.org6pak especially because the order is random, like wtf 12:27:17
@6pak:matrix.org6pakI thought that when I add nuget first then all the regular dependencies will be official12:27:37
@6pak:matrix.org6pakbut turns out if you add a nightly nuget repo for some random dependency, they can take over any package12:27:59
@gggkiller:matrix.orgGGGyeah12:28:06

Show newer messages


Back to Room ListRoom Version: 9