Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

These days, I equate anything that ships via docker/flatpak first as built by someone that only care about their own computer, especially if the project is opensource. As soon as a library or a tool update, they usually rush to add a hard condition on it for no reason other than to be on the "bleeding edge".
 help



I'm with you on this, but I do want to point out that a big reason that people will update bundled libraries like that is because they don't want to put the effort in to see whether their bundled library versions actually have any critical vulnerabilities that affect the project. It's easier to update everything and be sure that there are no critical vulnerabilities.

In other words, the Microsoft Windows update process as applied to software development.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: