4 ms·
I wish the number of "GopherCoins" put into "Dependency Management" was broken down into more pieces. Seems like dependencies are stupidly easy everywhere as l
by li2uR3ce 4y ago
I wish the number of "GopherCoins" put into "Dependency Management" was broken down into more pieces. Seems like dependencies are stupidly easy everywhere as long as you don't care about any kind of quality assurance. It's easy to get unvetted code running on your machines. Seems like I spend all my time trying to figure out if it's safe to depend on something while dependency management is usually purely a function of will it build/run.
And yes, this is an everywhere problem and therefore Go can't be faulted. And yes everyone's pet language has solved it anyway. Thankfully no one uses anything but silver bullets today. /s
Hard problems are still hard, I suppose.
- convolvatron 4y agounless you can describe the properties you care about and build a machine to automatically verify them, then its not clear what you're asking for or how it could possibly be solved.
- morelisp 4y agoDoes any other language's (common) dep tooling have something like the module proxy+sumdb? This is not sufficient but it's been a huge step forward for me to get some basic assurances that a) our upstreams are following at least base-level release practices, b) our team can't get spearphished, c) if we need to vet/blacklist/whatever, we have a single place in the infrastructure to do it.