Skip to content

Conversation

@wurstbrot
Copy link

In supply chain part is written:

Every organization must ensure an ongoing plan for monitoring, triaging, and applying updates or configuration changes for the lifetime of the application or portfolio.

This conflicts with:

* Deliberately choose which version of a dependency you use and upgrade only when there is need.

I understand that supply chain attacks vs. patch management is hard to guide on. But it should be clear what the recommendation is.

If the recommendation is to only patch when needed(e.g. a vulnerability exists), please explain more on the last sentences about monitoring/applying updates how that works together.

Removed recommendation to deliberately choose dependency versions.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant