Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

With a Gemfile and Gemfile.lock you really don't need to do any of that. The only thing that you will need to do is "bundle install" once your Ruby version is updated, which can be prevented by not updating Ruby. I just locked the ruby version in my package manager as I only use Ruby for Jekyll.

Other than that: if it works today, it should still work in a year, or 2 years, or 5 years.



> The only thing that you will need to do is "bundle install" once your Ruby version is updated, which can be prevented by not updating Ruby. I just locked the ruby version in my package manager as I only use Ruby for Jekyll.

I'm not sure that's a good idea. While you might avoid unexpected updates to Ruby, you'll also avoid security patches for CVEs.


Which CVEs are you going to find in a static website generator?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: