2 ms·
Thanks EwanToo - that makes perfect sense. A combination of some security monitoring system that notifies you of the vulnerabilities along with someone to upda
by JakeFratelli 15y ago
Thanks EwanToo - that makes perfect sense. A combination of some security monitoring system that notifies you of the vulnerabilities along with someone to update your system is needed. But what if the updates have dependencies, for instance, incompatible Ruby gems or so. At that point, do you have to make the tradeoff of security risk vs time to update all gems/resolve incompatibility issues/deal with bugs in latest release?
- EwanToo 15y agoExactly, if you've got a complex environment, you might not even know that one of your suppliers deployed an insecure ruby gem (or any other package), but you'll want to do full testing before upgrading. All this leaves big windows of opportunity for attacks.