Home
← all posts

#dependencies

  • Stop Using Yarn Classic

    May 7, 2026·5 min read

    Yarn Classic is frozen, and its lack of recursive transitive updates is becoming a real liability in an era where CVEs land weekly. It's time to move on.

    • #dependencies
    • #security
    • #yarn
    • #tooling
  • Protecting Against Compromised Packages with Minimum Release Age

    Apr 29, 2026·6 min read

    Leverage your package manager's minimum release age setting to delay the installation of freshly published versions and reduce the risk of pulling in a compromised package.

    • #dependencies
    • #security
    • #tooling
  • Minimizing Risk: Properly and Safely Resolving CVEs in Your Dependencies

    Oct 4, 2024·10 min read

    How to properly and safely update dependencies to resolve CVEs, while also gathering an understanding of how package managers handle dependencies.

    • #dependencies
    • #security
    • #tooling

Disclaimer|Privacy Policy
© 2021-present Nicolas Charpentier. All Rights Reserved.