Post #2198714
2025-12-15 12:18 UTC
@Richerpacker@mastodon.social @RachaelAva1024@tech.lgbt @millie@infosec.exchange I don’t quite understand the point you’re making. Yes, when there’s security updates to your dependencies, one must update. What is the alternative?
Replies (1)
-
@Richerpacker@mastodon.social 2025-12-15 13:10
@paula@hachyderm.io @RachaelAva1024@tech.lgbt @millie@infosec.exchange As I said, security updates shouldn't be avoided. But dependency can be updated for non-security/bugfix reasons. If you update your own software to accommodate, you impose updates onto all software that depends on yours. Soon, everybody updates because everybody updates.