|
|
|
|
|
by LtWorf
597 days ago
|
|
For some reason the "secure" thing to do is considered to be to pin everything and then continuously bump everything to latest, to get the security fixes. At which point one might directly not pin, but that's "insecure" (https://scorecard.dev/) |
|