3 ms·
> All dependencies sources must be included with project sources. This sounds great for applications. But for libraries, you'll likely end up with the diamond
by strager 5y ago
> All dependencies sources must be included with project sources.
This sounds great for applications. But for libraries, you'll likely end up with the diamond dependency problem: an application uses two libraries, and each library uses their own copy of a third library.
- vbezhenar 5y agoIn Java you have to decide which version application is going to use in the end. Maven decides that somewhat randomly. Gradle have some tricky algorithms to determine which version is highest one. You can put two versions of the same library on the classpath anyway, at least without some tricks with classloaders which are not used for ordinary applications. So basically with Java you would need to flatten all dependencies and resolve version conflicts in some way (sometimes you must downgrade one library or even declare that some libraries are not compatible with each other, but that's a rare occasion). AFAIK npm uses hierarchical dependencies, so few libraries with a different versions are not a problem at all (at least if those libraries are good citizens and don't pollute global namespace or use it carefully).
- shagie 5y agoMaven isn't random - it is described at https://maven.apache.org/guides/introduction/introduction-to-dependency-mechanism.html https://maven.apache.org/guides/introduction/introduction-to... > Dependency mediation - this determines what version of an artifact will be chosen when multiple versions are encountered as dependencies. Maven picks the "nearest definition". That is, it uses the version of the closest dependency to your project in the tree of dependencies. You can always guarantee a version by declaring it explicitly in your project's POM. Note that if two dependency versions are at the same depth in the dependency tree, the first declaration wins.
- vbezhenar 5y agoWell, in practice that turns out pretty random IMO. Nearest definition is meaningless. Order of declaration of dependencies is meaningless as well. It's not random in the sense that it does not change between builds if pom.xml not changed, but this deterministic algorithm does not make any sense, at least to me.