|
|
|
|
|
by EGreg
276 days ago
|
|
Exactly. I always tried to keep the dependencies to a minimum. Another thing you can do is lock versions to a year ago (this is what linux distros do) and wait for multiple audits of something, or lack of reports in the wild, before updating. |
|
(Big fan of version pinning in basically every context, too)