frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

You Should Not Update Your Dependencies

https://www.mendral.com/blog/you-should-not-update
20•OlivierCG•1h ago

Comments

0xbadcafebee•45m ago
It's another startup sales pitch. Their argument is the entire ecosystem is screwed, but it's okay, you can run their uber complicated toolchain in a CI pipeline and that will fix everything, by reviewing all of the code of your dependency updates. (because all the other backdoored code was never reviewed? because you're better at reviewing upstream code than the upstream maintainers?)

My take is the "hot take" nobody likes to hear. I think you should actually follow standard security best practices. Don't update constantly to the latest bleeding edge versions, but do update to the latest security patched versions. Do pin your versions (and SHA hashes of releases). Do keep an artifact repository. Do cryptographic verification of artifacts. Do validate every dependency you add, understand who made it, what it does. Do try to minimize your dependencies. Do review every new dependency and see what it is you're pulling into your application and whitelist the sources and their signed keys. Do use code signing. Do use OAuth, ephemeral keys, MFA, certificates.

Linux distributions have been secure for a long time by following these practices. Even their unstable branches. If they can do it, you can do it.

pdonis•22m ago
> It's another startup sales pitch.

Exactly. And for bonus points, the first part of the article seems to be arguing for the common sense stuff you describe--but then the article suddenly pivots to "use our new shiny tool instead". Huh?

jmclnx•30m ago
> The old operating model was indeed fine in a much smaller, simpler tech world,

The thing with the 'old days' that does not happen now is developers would go out of their way to make sure new releases were API backward compatible. Now it seems anything goes. If the API changed, a new function may be created or the old function would use variable arguments to allow the older functionality.

With that said, providing backward compatibility seems to be hard these days due to a BOM (Bill of material/dependencies) that make a BOM of submarine look simple.

That ssh/xz issue kind of highlighted how complex things have gotten.

johnea•1m ago
All of this is really about web dev, not s/w dev in general.

npm and pip are curses on the planet.

One point right from the beginning of the article: Why would you EVER leave a public port open straight to phpMyAdmin?

This is what SSH tunneling is for...

Can we have the day off?

https://mlsu.io/posts/day-off/
94•mlsu•27m ago•32 comments

YouTube to automatically label AI-generated videos

https://blog.youtube/news-and-events/improving-ai-labels-viewers-creators/
512•nopg•5h ago•305 comments

I think Anthropic and OpenAI have found product-market fit

https://simonwillison.net/2026/May/27/product-market-fit/
623•simonw•8h ago•770 comments

What Apple and Google are doing to push notifications

https://www.jacquescorbytuech.com/writing/what-apple-and-google-are-doing-your-push-notifications
165•iamacyborg•5h ago•167 comments

SimCity 3k in 4k (2025)

https://www.thran.uk/writ/hdid/2025/12/simcity-3k-in-4k.html
272•speckx•7h ago•105 comments

Rust (and Slint) on a Jailbroken Kindle

https://sverre.me/blog/rust-on-kindle/
96•homarp•5h ago•11 comments

A New Typst Template for Pandoc

https://imaginarytext.ca/posts/2025/typst-templates-for-pandoc/
23•ankitg12•1d ago•0 comments

DuckDuckGo search saw 28% more visits after Google said people love AI mode

https://www.pcgamer.com/hardware/duckduckgos-ai-free-search-saw-nearly-28-percent-more-visits-in-...
652•HelloUsername•8h ago•331 comments

Internet traffic in Iran increasing

https://radar.cloudflare.com/traffic/ir?dateRange=28d
60•Cider9986•2h ago•48 comments

Interleaved Deltas

https://mmapped.blog/posts/51-interleaved-deltas
27•surprisetalk•1d ago•0 comments

Pelica (YC P25) Is Hiring

https://www.ycombinator.com/companies/pelica/jobs/MDeC49o-machine-learning-engineer
1•lalitkundu•2h ago

FBI Arrests CIA Official with $40M in Gold Bars in His Home

https://www.nytimes.com/2026/05/27/us/politics/fbi-arrest-cia-official-gold-bars.html
40•cwwc•1h ago•9 comments

I'm Getting into Mesh Networks (Meshtastic, MeshCore, and Reticulum)

https://www.jonaharagon.com/posts/im-getting-into-mesh-networks-meshtastic-meshcore-and-reticulum/
46•Panda_•5h ago•17 comments

On Labubu and the Hyperreal

https://2earth.github.io/website/20260525.html
64•2earth•5h ago•72 comments

Go: Support for Generic Methods

https://github.com/golang/go/issues/77273
186•f311a•16h ago•143 comments

Incident with Pull Requests, Issues, Git Operations and API Requests

https://www.githubstatus.com/incidents/xy1tt3hs572m
257•maxnoe•12h ago•192 comments

Canada to order military plane fleet from Sweden in shift from US suppliers

https://www.theguardian.com/world/2026/may/27/canada-sweden-saab-globaleye-aircraft
399•tosh•8h ago•291 comments

Last.fm is now independent

https://support.last.fm/t/last-fm-is-now-independent/118591
615•twistslider•9h ago•174 comments

Claude Code as a Daily Driver: Claude.md, Skills, Subagents, Plugins, and MCPs

https://arps18.github.io/posts/claude-code-mastery/
364•arps18•19h ago•225 comments

Mini Micro Fantasy Computer

https://miniscript.org/MiniMicro/index.html#about
229•nicoloren•15h ago•80 comments

Gemini, Gophers, and Fingers. Oh My Alternative Internets Beyond HTTPS

https://brennan.day/gemini-gophers-and-fingers-oh-my-alternative-internets-beyond-https/
85•ChrisArchitect•7h ago•44 comments

Tech CEOs are apparently suffering from AI psychosis

https://techcrunch.com/2026/05/27/tech-ceos-are-apparently-suffering-from-ai-psychosis/
551•IAmGraydon•9h ago•283 comments

You Should Not Update Your Dependencies

https://www.mendral.com/blog/you-should-not-update
20•OlivierCG•1h ago•4 comments

Freediving, Embodiment and Humanity

https://tracesofhumanity.org/freediving-embodiment-and-humanity/
27•transpute•2d ago•13 comments

Human Bottlenecks

https://borretti.me/article/human-bottlenecks
75•zdw•3d ago•21 comments

Stress disrupts hippocampal integration of overlapping events, memory inference

https://www.science.org/doi/10.1126/sciadv.aea5496?user_id=66c4bf745d78644b3aa57b08
71•gmays•8h ago•12 comments

What Is a Direct Attach Copper (DAC) Cable? (2021)

https://www.servethehome.com/what-is-a-direct-attach-copper-dac-cable/
93•teleforce•2d ago•74 comments

I am not a black belt

https://rodolphoarruda.pro.br/i-am-not-a-black-belt/
7•rodolphoarruda•3d ago•6 comments

Private equity bought America's essential services

https://rubbishtalk.com/economy/how-private-equity-bought-americas-essential-services/
424•NoRagrets•13h ago•484 comments

Matrix Multiplications on GPUs Run Faster When Given “Predictable” Data (2024)

https://www.thonking.ai/p/strangely-matrix-multiplications
152•tosh•4d ago•43 comments