logoalt Hacker News

silverwindyesterday at 11:49 AM1 replyview on HN

Eventually you will want to update it, every update is a risk.


Replies

SkyPuncheryesterday at 1:39 PM

But, pinning has prevented most of the recent supply chain attacks.

As long as you don't update your pins during an active supply chain attack, the risk surface is rather low.