Hacker News new | ask | show | jobs
by hinkley 2320 days ago
Did that for a small Ivy-based project (Ivy is a simpler maven replacement) that had security implications.

We had a task every month for one developer to go manually upgrade one or two dependencies and commit the changes after testing (java libraries tend to upgrade much slower than Node).