Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The above is a general rule protecting you against supply chain attacks by default. If there is an important CVE published with a patch you can manually review that patch and bypass the minimum-age requirement for that dependency specifically.
 help



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: