4 ms·
Corollary: Do hard things more often, per Martin Fowler - https://martinfowler.com/bliki/FrequencyReducesDifficulty.html https://martinfowler.com/bliki/Frequenc
by web007 5y ago
Corollary: Do hard things more often, per Martin Fowler - https://martinfowler.com/bliki/FrequencyReducesDifficulty.html https://martinfowler.com/bliki/FrequencyReducesDifficulty.ht...
Upgrade everything all the time and it will never be hard. You'll have full context for breaking changes, and the diff from A to B is always smaller than from A to Q, and less likely to break in strange and confusing ways.
- rewgs 5y agoAbsolutely agree with this. Find the rest within staying in motion.
- snorkel 5y agoThis. Version pinning is just piling on the risk, and when a CVE is announced on the no-longer-supported version you’ve been pinned to for way too long then it’ll be a reactive emergency.
- naasking 5y agoKeeping up to date also has issues in the JS ecosystem. There were a couple of recent examples of npm packages that were hijacked and new versions released with embedded malware.
- Igelau 5y agoI'm in this camp. I ran into a recent situation where I could have used a drop-in security module if the project had updated the framework in the past decade. Instead we rolled our own, which is janky and took longer than it should have. Debts have a way of compounding. Tech debt is no exception. Tech debt begets tech debt begets tech debt, and it will hang on your velocity like a ball and chain.
- nlitened 5y agoDedicate 20% of developers’ time on constant updates of all components for a decade just in case you might need one drop-in security module ten years after now (if the company ever lives to see that day)? Does not sound like a good illustrative argument to me, I am afraid.
- chousuke 5y agoBut it doesn't work like that. You might reserve 20% of the time to chores, but you don't have to use all of that 20% every week. Efficiency of maintenance will improve after you get your processes and tooling in order and everyone has had a bit of experience with them, and the leftover time can be used for whatever the developers feel most deserves the extra time. The reason to do maintenance constantly is practice, which makes the difference between taking weeks or days vs. hours. When the time spent is evenly distributed, it's also less likely that an important task would be blocked by unavoidable maintenance.
- avidphantasm 5y agoIn my experience, upgrade everything all the time only works if you can keep your dependencies to a minimum, which can be harder in JS/TS land, but not impossible. I used to think every line of code you write is a liability, but have come to realize that every dependency is also a liability. So it’s about balancing the two.
- emptyparadise 5y agoEverything being on fire all the time makes your firefighting skills very valuable.