Hacker News
new
past
comments
ask
show
jobs
points
by
Tazerenix
18 hours ago
|
comments
by
jadar
7 hours ago
|
[-]
It almost doesn't matter, because you can get pwned by a transitive dependency. If someone doesn't have the same scruples as you have, you're still at risk.
reply
by
inbx0
4 hours ago
|
parent
|
[-]
minimumReleaseAge and lockfiles also pin down transitive dependencies.
reply