Hacker News new | past | comments | ask | show | jobs | submit login

I believe that's usually so they can track when a library has a security vulnerability and needs to be updated, regardless of whether the upstream package itself has a version that uses the fixed library.





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: