top | item 40307385

(no title)

rrwo | 1 year ago

A tool like that won't replace auditing dependencies.

The total age of dependencies tell you nothing useful.

discuss

order

OJFord|1 year ago

Nor did I claim it would. If you are auditing your dependencies like that then you don't need it, I said, as in it's not going to give you any extra information.

If you're not, and very many people are not, then total age of dependencies is a decent low-effort approximation for the probability of bug fixes affecting parts of dependencies that you're using.