3 ms·
> Every minute you spend "securing" your RELEASE NOTES is better spent securing the APPLICATION. I've never worked in a place where developer time is really th
by throwawayjava 9y ago
> Every minute you spend "securing" your RELEASE NOTES is better spent securing the APPLICATION.
I've never worked in a place where developer time is really that zero-sum.
If your release notes are executable code running on your infrastructure, then their security does matter.
I'm sure there's a team of developers at Avast who wish they had spent more time securing their "release notes".