▲ | gslepak 4 days ago | |||||||||||||||||||
> daily Somehow we've survived without updating dependencies for probably at least a year. | ||||||||||||||||||||
▲ | egorfine 3 days ago | parent [-] | |||||||||||||||||||
Then you probably have over a dozen CVEs in your code. Now, this is a different question whether they are exploitable and how much it is a risk. Other than that you now probably have an insurmountable technical debt and upgrading the dependencies is a project of itself. All the above applies to JavaScript world, of course. It's much different for the rest. | ||||||||||||||||||||
|