Copied to clipboard

Flag this post as spam?

This post will be reported to the moderators as potential spam to be looked at


  • Arjan H. 226 posts 463 karma points c-trib
    Jan 18, 2024 @ 09:32
    Arjan H.
    0

    Vulnerabilities in transitive packages/dependencies

    I'm wondering which approach people use to deal with vulnerabilities in transitive packages/dependencies? Do you manually update the transitive package with the risk of introducing compatibility issues and/or breaking changes? Or do you just wait until the maintainer of the direct dependency updates the (transitive) dependencies?

Please Sign in or register to post replies

Write your reply to:

Draft