3 ms·
This is a worrisome trend. Now one needs to manually check what the build system will fetch (and from where) before starting the build. Many times most of the
by intc 5y ago
This is a worrisome trend. Now one needs to manually check what the build system will fetch (and from where) before starting the build.
Many times most of the dependencies are available through the package manager of ones system.
A good way in my opinion is just to provide a clear list of the dependencies and make the build system complain if it's not there so one can install it (if didn't bother manually to check that the listed dependencies are present).
Of course there are very large and complex projects which may need more sophisticated solutions - Perhaps some sort code notarisation would serve well? Yet even there the dependency management should be clearly separated from the build system and it should prioritize using system provided packages when possible.
There are probably other considerations and implications too. Like preference of static linking over dynamic etc..