4 ms·
When you use `go get` to retrieve a version of a dependency, it adds a line to a `go.sum` while with a hash of the code at the version specified. You can distr
by Laremere 5y ago
When you use `go get` to retrieve a version of a dependency, it adds a line to a `go.sum` while with a hash of the code at the version specified. You can distribute your code without a copy of the dependency. When someone else runs go get on your module, it will attempt to retrieve the same version of the source, checking the hash. If the hashes are different, an error is thrown.
- fnord123 5y agoThat's what a Cargo.lock has. But it's recommended that you don't ship Cargo.lock that with libraries. I think the reason is because you can't have multiple versions of the same package. But I could be wrong. (If I'm wrong then you end up with horrific bloat with multiple trees of the same dep). What does go do when you have different deps depending on different versions of the same common dep?
- estebank 5y agoCargo.lock is ignored for libraries, it is only checked for binaries. https://doc.rust-lang.org/cargo/faq.html#why-do-binaries-have-cargolock-in-version-control-but-not-libraries https://doc.rust-lang.org/cargo/faq.html#why-do-binaries-hav... > If a library ends up being used transitively by several dependencies, it’s likely that just a single copy of the library is desired (based on semver compatibility). If Cargo used all of the dependencies' Cargo.lock files, then multiple copies of the library could be used, and perhaps even a version conflict. > In other words, libraries specify SemVer requirements for their dependencies but cannot see the full picture. Only end products like binaries have a full picture to decide what versions of dependencies should be used.
- verdverm 5y agoMinimum Version Selection (https://research.swtch.com/vgo-mvs https://research.swtch.com/vgo-mvs) tl;dr, Go does a BFS of the dep tree, selecting the maximum version found. There are no ranges, so you can only use a version which has been listed. "minimum" comes for a minimal implementation which can create reproducible results without a lockfile
- TheDong 5y agoThis is in the context of rust. > it adds a line to a `go.sum` while with a hash of the code at the version specified Cargo.lock also contains a checksum > You can distribute your code without a copy of the dependency Also true in rust, and the default way of using rust/cargo. > If the hashes are different, an error is thrown. Also true in rust. For an example of what this looks like: https://github.com/servo/webrender/blob/54b725be37f13b16694687ceab28b3fa6ac48921/Cargo.lock#L9-L16 https://github.com/servo/webrender/blob/54b725be37f13b166946... You haven't described anything different between go and rust in your comment since every feature you've pointed out applies equally to both.