4 ms·
Pinning dependencies also means you're missing any security fixes that come in after your pinned versions. That's asking for trouble too, so you need a mechanis
by Scramblejams 1y ago
Pinning dependencies also means you're missing any security fixes that come in after your pinned versions. That's asking for trouble too, so you need a mechanism by which you become aware of these fixes and either backport them or upgrade to versions containing them.
- kjkjadksj 1y agoAll code is fundamentally not ever secure.
- da_chicken 1y agoThat's why I run Windows 7. It's going to be insecure anyways so what's the big deal?
- apstls 1y agoThis statement is one of those useless exercises in pedantry like when people say "well technically coffee is a drug too, so..." Code with publicly-known weaknesses poses exponentially more danger than code with unknown weaknesses. It's like telling sysadmins to not waste time installing security patches because there are likely still vulnerabilities in the application. Great way to get n-day'd into a ransomware payment.
- nightpool 1y agoHave you spent time reviewing the security patches for any nontrivial application recently? 90% of them are worthless, the 10% that are actually useful are pretty easy to spot. It's not as big of a deal as people would like to have you think.
- yen223 1y agoThings like dependabot or renovate solves the problem of letting you know when security updates are available, letting you have your cake and eat it too.
- airtonix 1y ago[dead]
- skydhash 1y ago> so you need a mechanism by which you become aware of these fixes and either backport them or upgrade to versions containing them RSS Feeds?