
Keeping dependencies secure: semver, automation and their limits
Most of an application's code comes from dependencies. How semver and automated updates keep it secure, and what to do when an update can't.
Every change should reach production the same way, checked the same way. Pipelines, strict installs, automated updates and routine deployments.

Most of an application's code comes from dependencies. How semver and automated updates keep it secure, and what to do when an update can't.

During every deploy, old and new code share one database. How to change the schema without breaking either: expand, migrate, contract.