Fork your dependencies, trim them to only your use case, never update unless it breaks for your users. I’ve been vocal about this for 10+ years. I’ve always said that updating is way riskier than latent bugs (which can be tracked and CVEs monitored).
If you are updating a dependency, it’s on you to analyze every single commit in the full transitive set of dependencies. If you dont see anything compelling, dont update!
I remember at HashiCorp once in awhile an engineer would try to update a dep or replace a DIY lib with an external one and id always ask “show me the commit we need.” Dont update for the sake of it.
Feeling pretty swell about this mentality with all the supply chain attacks happening.
Just in case you'd like to learn IsiNdebele, there will be slots as from Wednesday, the 5th of November. DM your WhatsApp number to sign up. Please note that the lessons are online without an offline option.
Kindly RT and share widely with your networks.
#FundaIsiNdebele
In today’s fast-paced world, how do creatives stay inspired while meeting the constant demand for quality and speed? This October, we’re excited to host Warren Kirkland, Creative Lead at 5D, for an insightful session. Google Meeting: https://t.co/PLqqtXHxfb
Hmm, @NetOneCellular has been robbing me. Every time I put airtime, let's say, buying 15 dollar data bundle, if I put $15, it says your money insufficient funds
Please support my business.
I’m in harare and I make these aesthetic wall frames. A4 & A3 sizes available. I also courier to other cities. Call/App 0782775531🙏🏽 please rt
Hi, I make and sell customised aesthetic wall frames. I’m located in Harare 🇿🇼& deliver in cbd as well as other cities. Please rt, my customer could be on your tl❤️🙏🏽