cm0002@lemmings.world to Programmer Humor@programming.dev · 13 days agoShearing pointlemmy.caimagemessage-square11fedilinkarrow-up1251arrow-down15
arrow-up1246arrow-down1imageShearing pointlemmy.cacm0002@lemmings.world to Programmer Humor@programming.dev · 13 days agomessage-square11fedilink
minus-squaremormegil@programming.devlinkfedilinkarrow-up1·8 days agoAnother level of this dilemma: Pin all dependency versions – Prevents receiving security patches Don’t pin dependency versions – Enables supply chain attacks (see https://nesbitt.io/2026/02/03/incident-report-cve-2024-yikes.html)
Another level of this dilemma: