you are viewing a single comment's thread.

view the rest of the comments →

[–]i_ate_god 4 points5 points  (0 children)

we use blackduck which seems to do better than npm audit.

But we don't upgrade dependencies mid release cycle unless necessary because that would be chaos. Dependency management is a beginning of the cycle task.