3 ms·
If each package vendors its own deps, when the dep has a security vulnerability and needs an upgrade you need to hunt down every last location it exists in, ins
by chaosite 3y ago
If each package vendors its own deps, when the dep has a security vulnerability and needs an upgrade you need to hunt down every last location it exists in, instead of updating the single shared system dep and being done with it.
- somsak2 3y agowe just need better tooling for upgrading the individual locations. something like GitHubs dependabot