logoalt Hacker News

pabs3today at 8:36 AM1 replyview on HN

How many people actually audit the code changes in their dependencies when updating them?


Replies

mmariantoday at 1:27 PM

Few, if any. Which is why I'm highlighting that you can't just use commit SHA + Renovate then call it a day.