logoalt Hacker News

shortrounddev2yesterday at 12:24 PM2 repliesview on HN

it's interesting that staying up to date with your dependencies is considered a vulnerability in Node


Replies

bichiliadyesterday at 12:31 PM

Having a cooldown is different from never updating. I don’t think waiting a few days is a bad security practice in any environment, node or otherwise.

show 1 reply
skwee357yesterday at 12:31 PM

People who live on the edge of updates always risk vulnerabilities and incompatibility issues. It’s not about node, but anything software related.