Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
Every dependency you add is a supply chain attack waiting to happen | Better HN
Every dependency you add is a supply chain attack waiting to happen
(opens in new tab)
(benhoyt.com)
4 points
benhoyt
1mo ago
1 comments
Share
1 comments
default
newest
oldest
ArcHound
1mo ago
Yes, keep your dependencies low in numbers. No, don't turn off dependabot. Wait two weeks before updating. IIRC, there's a built-in feature for that.
j
/
k
navigate · click thread line to collapse