cm0002@lemmings.world to Programmer Humor@programming.dev · 1 month agoShearing pointlemmy.caimagemessage-square11fedilinkarrow-up1251arrow-down15
arrow-up1246arrow-down1imageShearing pointlemmy.cacm0002@lemmings.world to Programmer Humor@programming.dev · 1 month agomessage-square11fedilink
minus-squaremormegil@programming.devlinkfedilinkarrow-up1·27 days agoAnother level of this dilemma: Pin all dependency versions – Prevents receiving security patches Don’t pin dependency versions – Enables supply chain attacks (see https://nesbitt.io/2026/02/03/incident-report-cve-2024-yikes.html)
Another level of this dilemma: