5 ms·
What happens when the dependencies have bugfixes or security flaws? Why is it better to spread the responsibility for updates over all Go authors instead of to
by hdevalence 13y ago
What happens when the dependencies have bugfixes or security flaws? Why is it better to spread the responsibility for updates over all Go authors instead of to the authors of the libraries in question?
- nknighthb 13y agoYou make an explicit, knowledgable decision to update the dependency, like you should be doing with all software in a production environment.
- frowaway001 13y agoWhy is this supposed to involve tons of stupid stuff instead of adjusting a version number accordingly?
- mseepgood 13y ago> What happens when the dependencies have bugfixes or security flaws? Copy the new version into the repository, run the import rewriting script and check it in. > Why is it better to spread the responsibility for updates over all Go authors instead of to the authors of the libraries in question? Because you want to have full control over your dependencies. What if the author introduces a breaking change or removes the repository from the internet? Do you want to risk your business by being at the mercy of someone else's repository?
- gmjosack 13y agoWhat about when the library you want to use has a non-compatible license for distributing it with your source code?
- deleted 13y ago[deleted]
- burntsushi 13y agoUpdate them when you want. Just like you would with a package manager. If you need to stay up to date, then have something monitor their commit logs.