4 ms·
The dependencies can change out from underneath you transparently unless you pin everything all the way down the stack. Upstream docker images for example are a
by thinkingkong 5y ago
The dependencies can change out from underneath you transparently unless you pin everything all the way down the stack. Upstream docker images for example are an easy to understand vector of change. The deb packages can all change minor versions between runs, the npm packages (for example) can change their contents without making a version bump. Theres tons of implicit trust with all these tools, build wise.
- Osiris 5y agonpm packages can change without a version change? Can you explain this? npm doesn't allow you to delete any published versions (you can only deprecate them). You aren't allowed to publish a version that's already been published. Even when there have been malicious packages published the solution has been to publish newer versions of the package with the old code. There's no way to delete the malicious package (maybe npm internally can do it?).
- thinkingkong 5y agoSorry, without a minor version change. You can easily publish a patch version and most people don't pin that part of their dependency.
- LunaSea 5y agoThey don't need to pin it directly. They only need to "npm ci" (based on package-lock.json) instead of "npm install" (based on package.json) within the Docker container to get a fully reproducible build.
- pojzon 5y agoTbh I hope ppl do pin stuff to specific versions and have their own repositories of packages because you dont want to have external dependencies during builds that can fail. DevOps 101 more or less..