| ▲ | doodlesdev 7 hours ago | |||||||
How the hell is that actually a good thing? You might as well just use another language and disable Dependabot security updates if that's what you're looking for. Dependabot security updates aren't a liability, they're an asset in a world where developers use hundreds of dependencies daily, where every few months one of them is going to have a XSS or RCE vulnerability that has to be patched ASAP.
That's not how it works. Honestly, this blog post gets me really worried about this developer's projects and clients.
What the fuck. | ||||||||
| ▲ | wirelesspotat 7 hours ago | parent | next [-] | |||||||
I'm pretty sure the article is joking > If the vulnerability were critical, someone would have merged it by now. > GitHub Copilot can automatically suggest fixes for security vulnerabilities. Instead of updating to a patched version, let AI generate a workaround in your own code. | ||||||||
| ▲ | equinumerous 7 hours ago | parent | prev | next [-] | |||||||
The "> Remove lockfiles from version control" got me as well. > Reproducible builds sound nice in theory, but velocity matters more than determinism. Think of it as chaos engineering for your dependency tree. Reproducible builds are nice in practice, too. :) In the Node.js ecosystem, if you have enough dependencies, even obeying semver your dependencies will break your code. Pinning to specific versions is critical. | ||||||||
| ▲ | lanyard-textile 7 hours ago | parent | prev | next [-] | |||||||
I started to reevaluate the seriousness of this advice with the going to jail prompt. I probably should have caught on sooner :) | ||||||||
| ▲ | williamjackson 7 hours ago | parent | prev | next [-] | |||||||
Thank you for expressing my thoughts as well. The article seems to be full of contradictory “advice”. Use a dependency cooldown, okay … but don’t commit your lockfile so you are always running the latest transitive deps? That’s nuts. | ||||||||
| ||||||||
| ▲ | yunwal 6 hours ago | parent | prev [-] | |||||||
How did you reach "Set open-pull-requests-limit to zero" and not recognize this as satire? | ||||||||