<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[2020: the best thing you can do for security is have a bot automatically update your dependencies.]]></title><description><![CDATA[<p class="quote-inline">RE: <a href="https://fosstodon.org/@SocketSecurity/116321614885038368" rel="nofollow noopener"><span>https://</span><span>fosstodon.org/@SocketSecurity/</span><span>116321614885038368</span></a></p><p>2020: the best thing you can do for security is have a bot automatically update your dependencies. <br />2026: the best thing you can do for security is to tell your bot that updates dependencies to wait a day or three before updating them. </p><p>Expect more of this over the coming months as compromised credentials from previous supply chain attacks are used to mount new ones.</p>]]></description><link>https://board.circlewithadot.net/topic/37241f06-1288-4742-9e26-c07757779a63/2020-the-best-thing-you-can-do-for-security-is-have-a-bot-automatically-update-your-dependencies.</link><generator>RSS for Node</generator><lastBuildDate>Mon, 06 Apr 2026 04:04:04 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/37241f06-1288-4742-9e26-c07757779a63.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 31 Mar 2026 05:53:03 GMT</pubDate><ttl>60</ttl></channel></rss>