3 ms·
>If Github can start automatically recognizing dependencies I think that they already do this for JavaScript, Ruby, and Python dependencies[0]. However I don't
by asymptotically2 7y ago
>If Github can start automatically recognizing dependencies
I think that they already do this for JavaScript, Ruby, and Python dependencies[0]. However I don't think doing it automatically is the way to go, one dependency may be "worth" way more than another, and some dependencies may go undetected (e.g. if I conditionally sneak -lfoo into my LDLIBS somewhere)
[0]: https://github.blog/2017-11-16-introducing-security-alerts-on-github/ https://github.blog/2017-11-16-introducing-security-alerts-o...
- asdkhadsj 7y agoYea, definitely agree about automatically. For me the biggest problem with automatic is, exactly as you said, the worth of varying projects. I think automatic inclusion would also run the risk of OSS becoming less integrated. Ie, if I include another dependency I risk losing money, incentivizing me to reinvent wheels so long as I have the ability.