3 ms·
They have no concept of ever needing to reproduce a build. And they are probably right if you do continuous development of some SaaS stuff.
by _pmf_ 5y ago
They have no concept of ever needing to reproduce a build. And they are probably right if you do continuous development of some SaaS stuff.
- aranchelk 5y agoI’ve heard the argument that it’s not worth spending the time to get all aspects of your build environment into version control for 100% reproducible builds, but the saying “I shouldn’t be bothered to know what my upstream deps are” that’s pretty sad (hopefully rare). Even with the continuous deploy stuff, I think you’re giving too much benefit of the doubt. If an upstream non-pinned change brings down something critical (e.g. payments), you’ll revert the change in source, rebuild, release, the site is still broken. If you keep old artifacts you can push one of those, now you’re not really doing continuous deployment, and you won’t be again until you finish root cause analysis, and since you’ll never see the relevant change in your source code, it could take a while.