Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Fuck. Insecure defaults again. I argue that a version specifier should be only a hash. Nothing else is acceptable. Forget semantic versions. (Have some other method for determining upgrade compatibility you do out of band. You need to security audit every upgrade anyway). Process: old hash, new hash, diff code, security audit, compatibility audit (semver can be metadata), run tests, upgrade to new hash.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: