logoalt Hacker News

chrisweeklytoday at 12:30 PM0 repliesview on HN

"Security fixes aside" is too dismissive. Transitive dependencies with real CVEs can feel like the tail wagging the dog, but ignore them at your peril.