Hacker News new | ask | show | jobs
by dhab 1429 days ago
How do you know there are less vulnerabilities in a smaller package than there are in a better adopted one(usu bigger)? And isn’t it more likely that big packages (they got big I feel due to expanding user-base requirements) get the patch sooner?
1 comments

You can't have vulnerabilities in code which isn't there.

Compared to what I could be using, my ideal stack does not have: class loaders, virtual machines, dependency injection containers, web application servers, Log4J, etc.