We regularly ding companies that don't update dependencies. No offense, but how do developers sleep at night having their application littered with known vulnerabilities?
We regularly ding companies that don't update dependencies. No offense, but how do developers sleep at night having their application littered with known vulnerabilities?
The biggest correlated constant for bugs is that more lines of code = more bugs. As dependencies get updated they add more new features that I probably don't care about which adds more lines of code and therefore more bugs and security vulnerabilities.
I appreciate there is a balance between the two, but in my experience updating dependencies has broken things a lot more often than not updating things has broken things, and when that happens I find it a bit of a ridiculous idea that the maintainer has somehow made their product "more secure"(something that is usually a low dev priority) while at the same time introducing new bugs with the new features (something which is a higher dev priority) and they didn't even get that right.
I guess you just proved my point. Thanks.
Note: I'm not taking a stance on if I agree or not with this argument.
TBH most best practices preach for security by obscurity.
If you talk to any good vulnerabilities researcher - they will tell you what to really look out for.
Which means that their provider also did not run any dependency scans.
Tho if they fetched that from github open source repo -> yup thats just incompetence.