Copied to clipboard

Flag this post as spam?

This post will be reported to the moderators as potential spam to be looked at


  • Arjan H. 226 posts 463 karma points c-trib
    Jan 18, 2024 @ 09:32
    Arjan H.
    0

    Vulnerabilities in transitive packages/dependencies

    I'm wondering which approach people use to deal with vulnerabilities in transitive packages/dependencies? Do you manually update the transitive package with the risk of introducing compatibility issues and/or breaking changes? Or do you just wait until the maintainer of the direct dependency updates the (transitive) dependencies?

  • This forum is in read-only mode while we transition to the new forum.

    You can continue this topic on the new forum by tapping the "Continue discussion" link below.

Please Sign in or register to post replies