custard_swollower@lemmy.worldtoLinux@lemmy.ml•Lets Be Real About Dependencies | Comparing dependencies of C/C++ to Go/Rust
2·
12 days ago…and then you learn that packageX v1 is not maintained anymore and relies through a deep set of dependencies on a seriously vulnerable package (in a version which is also not maintained anymore).
Sorry, I had a pretty eventful December :)
This. Well put.