Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
Ygg2
6 months ago
|
parent
|
context
|
favorite
| on:
NIH is cheaper than the wrong dependency
If you fork a dependency and change features, the CVE information on original depenency is now no longer valid for your code. Your additions or removals can induce new CVEs, or render CVE for original lib a moot point.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: