4 ms·
Commit hashes seem to be the way to go, for sure, at least to be safe. I really don't want to put our vendor content in the repos. It's just a tad absurd when
by joaodlf 10y ago
Commit hashes seem to be the way to go, for sure, at least to be safe. I really don't want to put our vendor content in the repos.
It's just a tad absurd when you're used to mature package managers in other languages.
- eikenberry 10y agoBut they all have to vendor as well if they want reliable builds. Otherwise you end up with everything breaking when a developer decides to do a forced push or take his repo off github.
- stepik777 10y agoNot if there is a central repository which doesn't allow removal of packages.
- zellyn 10y agoWell, you can vendor, or you can have an internal mirror/cache of repositories.
- sdboyer 10y agoForce pushes - by far more common than straight-up repository removal - are handled without problem; we let you stick with your old version. (At least, that's how it should be - there might be a couple more test cases to write. I know I designed for this problem early on). Repo removal, renaming, or whatever, are still problems, for sure. Today, dep populates vendor/ with dependencies, and works equally well whether you decide to commit them or not.
- weberc2 10y agoHonestly, most package managers just bring their own problems. I'd rather commit source code than troubleshoot npm, pip, nix, maven, etc errors all day long. The only package manager I've found that works reliably has been Cargo (Rust).
- zellyn 10y agoThere has been a lot of talking between the committee that created `dep` and folks who've implemented other systems, including Cargo. I have high hopes.
- sdboyer 10y agoindeed, we've talked with them quite a bit :)
- RangerScience 10y agoI don't think I've ever had a problem with Bundler.
- OhSoHumble 10y agoMe neither. In fact, I rarely have trouble with package managers. They're amazing.
- weberc2 10y agoI envy you. I use Nix, pip, and npm on a daily basis and it's an uphill battle. I haven't used Bundler.
- OhSoHumble 10y agoWell, nix looks awfully complicated. I've had trouble deploying applications using pip. Npm hasn't given me any trouble. Bundler is lovely.
- vetinari 10y agoOnce I did 'sudo npm -g update npm', just 3.x to 3.x+1 and the hell broke loose. I had to wipe entire nodejs and reinstall from scratch. In other cases, 'npm update <package>' doesn't work and I have to do uninstall/install. Very common with typescript, for example.
- zellyn 10y agoI believe the current intended use is a human-editable "manifest file" where you specify desires/intent, preferably semver, ideally only as necessary, and a machine-generated "lock file" which specifies the actual hash of every transitive dependency, so builds are fully specified and reproducible.