cm0002@lemmings.world to Programmer Humor@programming.dev · 12 days agoShearing pointlemmy.caimagemessage-square11fedilinkarrow-up1248
arrow-up1248imageShearing pointlemmy.cacm0002@lemmings.world to Programmer Humor@programming.dev · 12 days agomessage-square11fedilink
minus-squaremormegil@programming.devlinkfedilinkarrow-up1·7 days agoAnother level of this dilemma: Pin all dependency versions – Prevents receiving security patches Don’t pin dependency versions – Enables supply chain attacks (see https://nesbitt.io/2026/02/03/incident-report-cve-2024-yikes.html)
Another level of this dilemma: