4 ms·
You claim that it's important to guarantee, with 100% certainty, that the version of a library you're getting in production is the one you expect. But then you
by Smudge 12y ago
You claim that it's important to guarantee, with 100% certainty, that the version of a library you're getting in production is the one you expect. But then you say it's not necessary to read through the entire diff if you check that library into source control. What if someone were to make a commit called "Updating jQuery to 2.1" but injected malicious code? Wouldn't that require another way of making sure your vendored files are from a trusted source? Would you still need to check them into source control?
- michaelmior 12y agoI don't recall making that claim.
- Smudge 12y agoYou're right -- my mistake. I mistook your comment for someone else's.