← Back to context

Comment by talon8635

12 hours ago

Your last point is the conundrum I keep running up against

It’s a trap regardless:

A) run a known vuln B) accept and run any and all updates immediately… which could be compromised

Maybe A is worse because it’s a known vuln?

AI auditing of dependency updates will mostly likely come soon (if it's not already there), and should mitigate the most obvious cases at least.

(By this I mean integrated in something like dependabot, not just some security companies doing it and publishing reports.)

I prefer the devil I know over the one I dont. At least I can make judgement calls with vulnerabilities im aware of. Automatic updates have unbounded risk.