Verifying what you did not write.
WHAT THE RISKS ARE
Behaviour changing on update Conflicts between components Security vulnerabilities Performance impact Abandonment
WHAT TO TEST BEFORE ADOPTING
That it does what is claimed Its behaviour at your data volume Its effect on performance Its behaviour when misconfigured
WHAT TO CHECK
Maintenance activity Known vulnerabilities Licence
WHAT TO TEST AFTER EVERY UPDATE
The functionality it provides Anything integrating with it Performance
WHY AFTER EVERY UPDATE
Third-party changes are not written for your use.
WHAT TO TEST ABOUT CONFLICTS
Components together, not only individually.
WHY
Conflicts appear only in combination.
WHAT TO PIN
Exact versions.
WHY
Automatic updates change behaviour without review.
WHAT TO MONITOR
Vulnerability announcements for everything you include.
WHAT TO PREPARE
A process for urgent updates.
WHAT TO TEST ABOUT REMOVAL
That a component can be removed without breaking things.
WHY
You may need to, urgently.
WHAT TO AVOID
Components so embedded they cannot be replaced.