logoalt Hacker News

philipwhiukyesterday at 5:29 PM1 replyview on HN

I think everyone just gets hit after 7 days frankly.


Replies

pixl97yesterday at 5:47 PM

Why? Everyone won't use cooldowns, but the key is to have just enough people running brand new to set off a warning/have systems that check dependencies scan and find vulns go off and the packages get pulled before production builds them.

Monocultures where everyone pulls and builds with every brand new thing for the most minor changes is dangerous.