3 ms·
you just update them and that's it? Usually, there are CI/CD pipelines, but also change and testing regimes of some sort. Dev/QA too before prod. Here is my s
by notepad0x90 4mo ago
you just update them and that's it?
Usually, there are CI/CD pipelines, but also change and testing regimes of some sort. Dev/QA too before prod.
Here is my suggestion though:
- Don't use package repos on the internet, host local caches
- Update your package caches twice a week, not more frequently
- Unpin and update packages in dev as it makes sense, as soon as the package repos update
- QA whenever your team can actually do testing
- Prod, with your next release, no more frequently than 90 days
There is a reason public CVE disclosure is ballpark 90 days per ethical security research and testing norms. That's how long proper testing and release is expected to take.
If you have no specific reason to update a package, and it passes integration tests with more up to date packages, then don't update. Supply chain compromises aside, bugs have a way of creeping. Things get missed with tests. Either you take this careful approach, or you take the other extreme approach where you design everything so well and with so much costly infrastructure and people to manage it, that impact is priced into the availability and threat modeling, which almost no one can pull off except on paper (well.. I said almost...).