This might be a stupid question, but can someone explain to me what this means? Thanks!
This might be a stupid question, but can someone explain to me what this means? Thanks!
Updating code you depend on is a semi-manual process - you choose to copy the latest version of the code you depend on into your project again.
This is contrast to stacks like Java, where I can give you a pre-compiled JAR file that you can link your code to.
git subrepo pull --all
is enough to update all dependencies.> Top Tip — Libraries should never vendor their dependencies.
Peter goes on to clarify:
> You can carve out an exception for yourself if your library has hermetically sealed its dependencies, so that none of them escape to the exported (public) API layer. No dependent types referenced in any exported functions, method signatures, structures—anything.
I think this is the way to go if you're writing a library which has its own dependencies. You get a repeatable build and free yourself to change which dependencies you rely on without impacting users of your package.
There are exceptions, such as if your dependency has an init which only makes sense to run once. Loggers come to mind, where the setup should be determined by the main package. The f.Logger point in the article is friendlier to users of your package than just using log.Printf, and frees you from having to vendor logrus, for example, if you want to support structured logging.