Post #2198712
2025-12-15 12:00 UTC
@RachaelAva1024@tech.lgbt @millie@infosec.exchange
I agree that zero updates are an illusion, security is a good example.
However, you just said that we must update because the dependencies had updates.
Let that sink for a moment.
Replies (2)
-
@RachaelAva1024@tech.lgbt 2025-12-15 12:18
@Richerpacker@mastodon.social @millie@infosec.exchange …Fair enough. Still though, some common ground needs to be made in the case of security and bug fixes in the dependencies. For example, not updating the program anytime a dependency is updated, but maybe once every few months or when a critical security bug fix is available.
-
@paula@hachyderm.io 2025-12-15 12:18
@Richerpacker@mastodon.social @RachaelAva1024@tech.lgbt @millie@infosec.exchange I don’t quite understand the point you’re making. Yes, when there’s security updates to your dependencies, one must update. What is the alternative?