3 ms·
On the other hand, how do developers sleep at night after updating their dependencies as it will now be littered with new unknown vulnerabilities. The biggest
by fizzynut 4y ago
On the other hand, how do developers sleep at night after updating their dependencies as it will now be littered with new unknown vulnerabilities.
The biggest correlated constant for bugs is that more lines of code = more bugs. As dependencies get updated they add more new features that I probably don't care about which adds more lines of code and therefore more bugs and security vulnerabilities.
I appreciate there is a balance between the two, but in my experience updating dependencies has broken things a lot more often than not updating things has broken things, and when that happens I find it a bit of a ridiculous idea that the maintainer has somehow made their product "more secure"(something that is usually a low dev priority) while at the same time introducing new bugs with the new features (something which is a higher dev priority) and they didn't even get that right.
- mbesto 4y ago> (something that is usually a low dev priority) I guess you just proved my point. Thanks.