Vulnerabilities in transitive packages/dependencies #15601
Replies: 2 comments 1 reply
-
It depends.. |
Beta Was this translation helpful? Give feedback.
-
@bergmania Thanks for the quick reply. Just to get our terminology straight:
So when there's a vulnerability in a transitive Umbraco dependency (4) which can be updated by the project developer (1) Umbraco waits for the maintainer of the direct Umbraco dependency (3) to update the vulnerable transitive Umbraco dependency. Correct? So Umbraco does not update any vulnerable transitive Umbraco dependencies (4) effectively making them a direct Umbraco dependency (3)? In your experience what is the risk of upgrading the transitive dependencies in the developer project, since this could potentially introduce compatibility issues and/or breaking changes. |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
I'm wondering which approach Umbraco takes and advises regarding vulnerabilities in transitive packages/dependencies?
Beta Was this translation helpful? Give feedback.
All reactions