Comment by talon8635
12 hours ago
Your last point is the conundrum I keep running up against
It’s a trap regardless:
A) run a known vuln B) accept and run any and all updates immediately… which could be compromised
Maybe A is worse because it’s a known vuln?
AI auditing of dependency updates will mostly likely come soon (if it's not already there), and should mitigate the most obvious cases at least.
(By this I mean integrated in something like dependabot, not just some security companies doing it and publishing reports.)
I prefer the devil I know over the one I dont. At least I can make judgement calls with vulnerabilities im aware of. Automatic updates have unbounded risk.