←back to thread

1369 points universesquid | 1 comments | | HN request time: 0s | source
Show context
koolba ◴[] No.45171232[source]
Another great example of why things like dependabot or renovate for automatically bumping dependencies to the latest versions is not a good idea. If it's not a critical update, better to let the world be your guinea pig and only update after there's been a while of real world usage and analysis. If it is a critical enough update that you have to update right away, then you take the time to manually research what's in the package, what changed, and why it is being updated.
replies(2): >>45173904 #>>45174096 #
1. chuckadams ◴[] No.45173904[source]
If the update isn't from a security alert, I let most dependabot PRs marinate for about a week precisely for this reason. Not the most scientific approach, but less stressful for sure.