3 ms·
But, not having the time to review 198 updates shouldn’t justify automatically permitting the updates. I agree there isn’t time to review them, unless you have
by wainstead 6y ago
But, not having the time to review 198 updates shouldn’t justify automatically permitting the updates.
I agree there isn’t time to review them, unless you have plenty of staff and time (no one does)... but the recent Solarwinds debacle was a supply chain attack, and automatic updates allowed an exploit to be propagated to many companies and agencies.
I would ask myself if I need that many packages. And raise the red flag with management that maintaining proper security is a challenge under such circumstances.
- chris_wot 6y agoHow would reading release notes help in the case of the Solarwinds attack?