4 ms·
I feel the real issue here is downstream package consumers not practicing proper dependency pinning. You can blame the Node ecosystem, the maintainer of the pac
by odensc 6y ago
I feel the real issue here is downstream package consumers not practicing proper dependency pinning. You can blame the Node ecosystem, the maintainer of the package, etc. but there are well-known solutions to prevent this kind of situation.
- thawkins 6y agoSo you would exchange security for stability, if you use package pinning then you will end up with fosilized packages in your product, which will have all maner of security issues that have alresdy been fixed.
- flukus 6y agoIf a package doesn't provide a stable branch that will receive security updates then it's not mature enough to be used anyway. That's the sensible middle ground between bleeding edge and security, unfortunately most packages/projects aren't mature enough to provide this. There's a reason companies stick with old COBOL solutions, modern alternatives simply aren't stable enough.
- deleted 6y ago[deleted]
- linkgoron 6y agoYou can always use something like dependabot, which should help you quickly upgrade versions and also protect you from breaking your build.
- rhizome 6y agoI get notifications to update my Rails apps from GitHub as a matter of course when there's a CVE in my dependencies. Does this kind of thing not exist/is impractical for JS?
- hobofan 6y agoFrom my experience of getting ~30 of those notifications per week for a handful of JS repos, I can very much assure you that it does exist.
- odensc 6y agoAs a fellow commenter said, you would ideally use something like dependabot or greenkeeper/snyk.
- Vinnl 6y agoThis wasn't a big problem due to a package being suddenly upgraded in existing code. It's because a scaffolding tool (Create React App) used to set up new projects would set those projects up with the latest (presumably patch, maybe minor) version of the dependencies. In other words, because those projects did not exist yet, there was nothing to pin. Unless you mean Create React App should pin all of their (transitive) dependencies and release new versions multiple times a day with one of those dependencies updated.