logoalt Hacker News

rcxdudelast Sunday at 10:29 PM0 repliesview on HN

You can avoid all those worries by vendoring the code anyway. you only 'need' to update it if you are pulling it in as a separate dependency.