Fork your dependencies, trim them to only your use case, never update unless it breaks for your users. I’ve been vocal about this for 10+ years. I’ve always said that updating is way riskier than latent bugs (which can be tracked and CVEs monitored). If you are updating a depen…↗
·@mitchellh·May 22, 2026·essay·cve-monitoring·dependency-management·supply-chain-security·update-policy