Skip to content
Better HN
Top
Best
Ask
Show
New
Jobs
Search
⌘K
Every dependency you add is a supply chain attack waiting to happen
(opens in new tab)
(benhoyt.com)
4 points
benhoyt
2mo ago
1 comments
Save
Share
1 comments
1 comments · 1 top-level
top
newest
oldest
ArcHound
2mo ago
Yes, keep your dependencies low in numbers. No, don't turn off dependabot. Wait two weeks before updating. IIRC, there's a built-in feature for that.
j
/
k
navigate · click thread line to collapse