Remix.run Logo
▲ otterley 2 hours ago

> Vendoring isn't a clear win for security. It may provide some protection against "supply chain" attacks, but makes it more difficult for you to respond to vulnerabilities discovered in the version you vendored.

How so? Whether a dependency is vendored or not, you still have to update it to integrate a security update to that dependency, don't you? The alternative is to not pin your dependencies, but that is far riskier overall.

> Whether or not the benefits are worth the inconvenience is a different question

I would contend that it is the most important question. :-)