3 ms·
The idea is that the safety delay would protect your organization from automatically (and in many cases unintentionally) updating to a new compromised dependenc
by sumstrem 5y ago
The idea is that the safety delay would protect your organization from automatically (and in many cases unintentionally) updating to a new compromised dependency version, where you are unaware of a problem.
In the case with security fixes and patches, you would be aware that a security issue exists and, if needed, could manually add the security patch either to the same registry or to another registry where you have complete control over the versions allowed.
- taubek 5y agoOh, I see it. I didn't quit get that part correctly.