(no title)
syvolt | 1 year ago
I'm not a library author and I try to be careful about what dependencies I introduce to my projects (including indirect dependencies). On one project, switching to `go tool` makes my go.mod go from 93 lines to 247 (excluding the tools themselves) - this makes it infeasible to manually review.
If I'm only using a single feature of a multi-purpose tool for example, does it matter to me that some unrelated dependency of theirs has a security issue?
wakawaka28|1 year ago
How is anyone supposed to know whether there's an issue or not? To simplify things, if you use the tool and the dependency belongs to the tool, then the issue can affect you. Anything more advanced than that requires analyzing the code.
syvolt|1 year ago
verdverm|1 year ago
arccy|1 year ago
now, do you care about some development tool you're running locally has a security issue? if yes, you needed to update anyway, if not, nothing changes.