cm0002@lemmings.world to Programmer Humor@programming.dev · 7 days agoShearing pointlemmy.caimagemessage-square11linkfedilinkarrow-up1250arrow-down15
arrow-up1245arrow-down1imageShearing pointlemmy.cacm0002@lemmings.world to Programmer Humor@programming.dev · 7 days agomessage-square11linkfedilink
minus-squaremormegil@programming.devlinkfedilinkarrow-up1·2 days agoAnother level of this dilemma: Pin all dependency versions – Prevents receiving security patches Don’t pin dependency versions – Enables supply chain attacks (see https://nesbitt.io/2026/02/03/incident-report-cve-2024-yikes.html)
Another level of this dilemma: