• earthworm@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    14
    ·
    1 day ago

    The careful reader may note that my title is not quite accurate. It’s not every dependency you add that’s a problem; it’s every dependency you update.

    Why not put that in the title, Mr. Hoyt?

      • corsicanguppy@lemmy.ca
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 day ago

        Every dependency you don’t update is a zero day waiting to happen. All software carries risk.

        In the same breath you’re advocating updating without checking, and saying why that’s an issue. You … realize that, right?

        You’re so close to realising the reason enterprise distros do backports.

        • renegadespork@lemmy.jelliefrontier.net
          link
          fedilink
          English
          arrow-up
          2
          ·
          22 hours ago

          you’re advocating updating without checking,

          Uh… no. That’s not what I said. I said there’s risk in both updating and not updating. You need to do the assessment to decide which one is best for the situation.