|
|
|
|
|
by fsloth
396 days ago
|
|
I don’t believe anything I wrote above promotes the idea of ignoring vulnerabilities as a standard procedure. CVE database is an excellent way to be informed about vulnerabilities and there are services to automatically map CVE reports to code bases. |
|
What's the alternative? Are you suggesting that backpatching transitive deps dating back over a decade-plus tineframe is a viable maintenance strategy?