Hacker News new | ask | show | jobs
by chrisweekly 96 days ago
"Security fixes aside" is too dismissive. Transitive dependencies with real CVEs can feel like the tail wagging the dog, but ignore them at your peril.