|
|
|
|
|
by pwdisswordfish0
1699 days ago
|
|
> And what happens when you need to update those dependencies? Then you update them just like you do otherwise, like I already said is possible. > you can't keep it alive on 4yr-old dependencies. In fact, you've cursed it with unpatched bugs and security issues This is misdirection. No one is arguing for the bad thing you're trying to bring up. Commit your dependencies. |
|
Now you have malware in your local repo :(
Having a local repo does not prevent malware. Your exposure to risk is less because you update your dependencies less frequently, but the risk still exists and needs to be managed. There's no silver bullet.