Hacker News new | ask | show | jobs
by silicon2401 1547 days ago
The opposite could also be true. Now that I have experience working on vulnerabilities for enterprise software, I've learned there are constantly updates for mitigating software vulnerabilities that didn't exist a month or even week ago. An old java project may still use a version log4j with that major vulnerability. This may not be a big deal depending on the software, but it is a valid reason to be wary of stale code in some cases.