3 ms·
That approach might have worked 20 years ago when a big project had more than 3 3rd-party libraries and CPAN was the pinnacle of dependency management, but it's
by goldbrick 11y ago
That approach might have worked 20 years ago when a big project had more than 3 3rd-party libraries and CPAN was the pinnacle of dependency management, but it's burying your head in the sand in this day and age. Security patches are a fact of life, and unless you've air-gapped everything, aren't optional. Sooner or later you're bound to run into bug fixes or api improvements that will force your hand as well. Not being proactive about keeping your dependencies up to date is like only eating dessert and never eating vegetables.
- donatj 11y agoBeing overly proactive is just as bad. The majority of the bugs haven't been in there since the init commit, they were added over time. Often you are just swapping known bugs for unknown bugs (which is arguably worse) particularly when the update contains more than just a tiny bug fix.