3 ms·
Within google, google’s own open source software is treated as “third party”. https://opensource.google.com/docs/thirdparty/ https://opensource.google.com/docs
by fourth_party 9y ago
Within google, google’s own open source software is treated as “third party”.
https://opensource.google.com/docs/thirdparty/ https://opensource.google.com/docs/thirdparty/
- jzelinskie 9y agoThanks for the response. Are things moving into third party or are new projects being created in third party and maintained alongside the originals? I and probably many others are more likely to be willing to depend on a library if I know Google internals directly depend on the maintenance of said library.
- yegle 9y agoLikely no one would answer this question considering the info is confidential. I think the best way to understand how Google uses a monorepo is this doc [0]. Disclaimer: yes I work for Google but my work is not related to Abseil team. [0]: https://cacm.acm.org/magazines/2016/7/204032-why-google-stores-billions-of-lines-of-code-in-a-single-repository/fulltext https://cacm.acm.org/magazines/2016/7/204032-why-google-stor...
- joshuamorton 9y agoParroting this comment (that is probably confidential), the abseil website does include this statement: >The libraries we are releasing come with a pedigree: many years of experience using these APIs in Google’s production environments. We’ve seen what works and what doesn’t, what designs lead to bugs, performance problems, and misuse. What you see here is what we found to be a good balance between simplicity and meeting the needs of production use and an ever-evolving codebase. [1] Also a googler who has nothing to do with abseil. [1]: https://abseil.io/ https://abseil.io/
- ehnto 9y agoI have always wondered how the monorepo design works in regards to more sensitive pieces of code. For example some of the key algorithms behind search.
- joshuamorton 9y ago>Since Google's source code is one of the company's most important assets, security features are a key consideration in Piper's design. Piper supports file-level access control lists. Most of the repository is visible to all Piper users;d however, important configuration files or files including business-critical algorithms can be more tightly controlled. In addition, read and write access to files in Piper is logged. If sensitive data is accidentally committed to Piper, the file in question can be purged. The read logs allow administrators to determine if anyone accessed the problematic file before it was removed. From [1]. Essentially, there are files and changes that I cannot view the source of. [1]: https://cacm.acm.org/magazines/2016/7/204032-why-google-stores-billions-of-lines-of-code-in-a-single-repository/fulltext https://cacm.acm.org/magazines/2016/7/204032-why-google-stor...
- kerneis 9y agoBut where the real magic happens is that you can still build them, even if you cannot read them, if they are required as (direct or indirect) dependencies of your code.