3 ms·
> Aren't migrations good on some aspects such as force engineers to stop using insecure libraries? Sure, but how many times have you deployed an update that yo
by Normal_gaussian 5y ago
> Aren't migrations good on some aspects such as force engineers to stop using insecure libraries?
Sure, but how many times have you deployed an update that you were sure was security? Most libs I work with are 90+% features or ease-of-use releases, the security is hand wavy to do with dependencies, or a very rare "oops".
- mattnewton 5y agoThis is mitigated somewhat by having integration tests (which shine in migration-like situations like this despite their many other problems). You can write tests that defend you from some of the breakages at Google and guarantee they will be run.
- pkhuong 5y agoAnd the ability to run automatically run tests on any part of the code base because everything uses Blaze. You can schedule your wide-reaching changes on the TAP train and see what breaks across the whole monorepo. In most cases, the library authors are responsible for driving the migration. This is different from third-party libraries adding causing pain to everyone else because they decided to change an interface without sending PRs to migrate all their users.