▲ | stickfigure 4 days ago | |||||||
It wouldn't be a problem if there wasn't a culture of "just upgrade everything all the time" in the javascript ecosystem. We generally don't have this problem with Java libraries, because people pick versions and don't upgrade unless there's good reason. | ||||||||
▲ | ilvez 4 days ago | parent | next [-] | |||||||
From maintenance perspective both never and always seem like extremes though. Upgrading when falling off the train is serious drawback on moving fast.. | ||||||||
| ||||||||
▲ | jcelerier 4 days ago | parent | prev [-] | |||||||
and then you get Log4Shell |