Running software applications in production today is crazy. One point release opens up for supply chain attacks. What’s crazier is not running your production applications without a lock file, potentially running dependencies you’ve never ran before for the first time in prod.
Note
This post is a thought. It’s a short note that I make about someone else’s content online #thoughts