Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That's indeed reasonable, but the opposite can happen just as well: there is a vulnerability in the western calendar, but I'm on an old major.minor version that receives no security patches anymore. So now I have to upgrade that dependency, potentially triggering an avalanche of incompatibilities with other packages, leading to further upgrades and associated breakages. Oopsie.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: