cm0002@lemmings.world to Programmer Humor@programming.dev · 6 days agoShearing pointlemmy.caimagemessage-square11linkfedilinkarrow-up1249arrow-down15
arrow-up1244arrow-down1imageShearing pointlemmy.cacm0002@lemmings.world to Programmer Humor@programming.dev · 6 days agomessage-square11linkfedilink
minus-squaremormegil@programming.devlinkfedilinkarrow-up1·18 hours agoAnother level of this dilemma: Pin all dependency versions – Prevents receiving security patches Don’t pin dependency versions – Enables supply chain attacks (see https://nesbitt.io/2026/02/03/incident-report-cve-2024-yikes.html)
Another level of this dilemma: