I'm on Open Source Security: Updating open source dependencies

60 · Jamie Tanna · Dec. 8, 2025, 9:11 a.m.
Summary
The author reflects on their experience discussing open source dependency management on the Open Source Security podcast, focusing on the Renovate project and its recent features aimed at enhancing ecosystem security after critical vulnerabilities like the Sha1-Hulud attack. The post emphasizes the complexities of updating dependencies and the ongoing challenges within the field.