logoalt Hacker News

NetMageSCWtoday at 8:00 AM1 replyview on HN

Because they could have a security flaw that might compromise your project or any users of it.


Replies

vablingstoday at 2:44 PM

For any of my rust projects I really don't bump my deps unless dependabot shows a serious vulnerability or I want to use a new feature added. Outside of that my deps are locked to the last known good version i use.