|
|
|
|
|
by djsumdog
2628 days ago
|
|
They also mention in the article how they don't support skipping releases, so it sounds like you have to upgrade to each point release anyway? Really if you're not constantly updating dependencies as part of your pipelines, you're going to quickly get into dependency rot issues. |
|
Do it this way and save yourself the pain of zillions of updates when you HAVE to bump a package for a CVE.