logoalt Hacker News

andrepdyesterday at 9:39 PM1 replyview on HN

Only if that different version is a dependency of a dependency. Your own will never change.


Replies

brabelyesterday at 10:01 PM

That does not make the problem go away: now you'll have both versions in your dependency graph - hence you may be vulnerable to both version's CVEs.

show 1 reply