logoalt Hacker News

pabs3today at 8:39 AM0 repliesview on HN

Better to treat it as a dependency still, but audit each new commit/release as it comes in, and pin to the exact last commit id that you verified.