logoalt Hacker News

0x500x79today at 4:09 AM1 replyview on HN

Pin your dependencies folks! Audit and don't upgrade to every brand new version.


Replies

onion2ktoday at 4:30 AM

But also have a regular review of your dependencies to update them when necessary, because as bad as compromised packages may be things do have vulnerabilities occasionally, and upgrading things that are a long way out-of-date can be quite hard.