Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
wildpeaks
on April 25, 2020
|
parent
|
context
|
favorite
| on:
A one-line package broke `npm create-react-app`
Exactly: pin dependencies to avoid surprises, and use a CI to test compatibility of new versions, so you can deploy security updates on your own schedule, best of both worlds.
Github even bought Dependabot last year, so it's now free.
Consider applying for YC's Summer 2026 batch! Applications are open till May 4
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search:
Github even bought Dependabot last year, so it's now free.