logoalt Hacker News

nineteen999yesterday at 2:23 AM1 replyview on HN

> Install it once and never update it (and therefore hacked and malicious versions can never arrive in your dependency tree).

Huh? What if your once-off installation or vendoring IS a hacked an malicious version and you never realise and never update it. That's worse.


Replies

llbbddyesterday at 4:39 AM

Hardly worth responding to, from other comments they're defending Java. They're not used to updates.