Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

it's interesting that staying up to date with your dependencies is considered a vulnerability in Node


Having a cooldown is different from never updating. I don’t think waiting a few days is a bad security practice in any environment, node or otherwise.


But only if most of everyone else doesn't do so.


People who live on the edge of updates always risk vulnerabilities and incompatibility issues. It’s not about node, but anything software related.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: