5 ms·
As with almost every software in the world, silent version changes may break things. This is why npm, bower, rubygems, maven, python's requirement.txt and almos
by Pharaoh2 11y ago
As with almost every software in the world, silent version changes may break things. This is why npm, bower, rubygems, maven, python's requirement.txt and almost every other package management system allows you to specify the exact version of a dependency and begs you to use it in production. This is also why you need a staging environment that is as close as possible mirror of production.
Seems like you failed to RTFM
- edp 11y agoAll our dependencies in maven and bower are locked down. However, even though you can do the same with a buildpack, this is not exactly what heroku and dokku will do by default. The documentation [0] specifies a way to do so with a git based system, but all commands given on that page won't specify a tag. Note that this was not in production, like I said in the article, it was an internal release. [0] https://devcenter.heroku.com/articles/buildpacks https://devcenter.heroku.com/articles/buildpacks
- josegonzalez 11y agoDokku/herokuish do indeed lock down to specific buildpacks [1]. You just happened to use a method that allowed you to use any version of that buildpack (multi-buildpack, which is provided by Heroku itself). [1] https://github.com/gliderlabs/herokuish/tree/master/buildpacks https://github.com/gliderlabs/herokuish/tree/master/buildpac...