Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Your last point is the conundrum I keep running up against

It’s a trap regardless:

A) run a known vuln B) accept and run any and all updates immediately… which could be compromised

Maybe A is worse because it’s a known vuln?



I prefer the devil I know over the one I dont. At least I can make judgement calls with vulnerabilities im aware of. Automatic updates have unbounded risk.


AI auditing of dependency updates will mostly likely come soon (if it's not already there), and should mitigate the most obvious cases at least.

(By this I mean integrated in something like dependabot, not just some security companies doing it and publishing reports.)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: