4 ms·
Totally disagree about dependency management. If you check them into your repo, people who use your repo to build do not need to fetch other dependencies which
by codemac 11y ago
Totally disagree about dependency management. If you check them into your repo, people who use your repo to build do not need to fetch other dependencies which may or may not exist over the network anymore. This is especially true if you ever intend to build an old version of your software.
And if your library doesn't support multiple platforms, I'm not sure I fully understand how omitting the source code of a dependency from your repo magically gives you platform independence.
- EvanPlaice 11y ago1. They pollute the source history with code that doesn't relate to the project. Every time I see a repo for a trivial application that has 100K+ LOC I think, "wow... this person clearly doesn't understand how to use package management tools". Dependencies should be clearly outlined in the config and easily setup using a package manager. You can either download the deps source from your repo or you can download it from a package manager, either way you'll need to download it. 2. If your dist requires a compilation stage, it will likely generate binaries targeted specifically to the architecture they're compiled on. Automating the compilation stage enables users to compile the source to work on their specific architecture (ie hence platform independence). 3. Dependencies should be frequently updated and tested against the latest. Not doing so potentially exposes you to bugs and/or security risks that may be included in future updates. If your app has relatively good test coverage there's no reason you shouldn't be using the latest minor version for all of your dependencies. Not doing so is assuming responsibility for the consequences of running stale code.