← Back to context

Comment by nedt

4 hours ago

But then at the same time you should always update because it might fix a security vulnerability. Otherwise you end up running nodejs 10 because you don't need the new stuff.

Or it might introduce one. But sure, a security fix for a known vulnerability could count as something you need in a new version. Ideally they would be backported and separated from feature updates. The constant dependency churn and single-channel update stream is kind of why a lot of vulnerabilities become problems in the first place.