3 ms·
> what can be done to address this type of issue? Only auto-upgrade for security fixes. For all others, wait between month to a year to update a dependency, un
by throwaway984393 5y ago
> what can be done to address this type of issue?
Only auto-upgrade for security fixes. For all others, wait between month to a year to update a dependency, unless one specifically fixes a bug you are experiencing.
- Gigachad 5y agoNPM tells me that just about everything is a security issue. Apparently my linter has a critical security issue because I could put a malicious regex in my own linter config causing it to waste cpu..
- throwaway984393 5y agoYou can also check the CVE and see if it's critical (or if it even affects your application) and wait if it's not. Security literacy makes your life easier.
- UncleMeat 5y agoThis works for OSS code but not for all dependencies in general. That SDK or whatever you are using likely isn't getting CVEs filed on it.