Are you checking your dependencies into your repository (we do this, it works very well).
If not, are you pinning specific commit hashes? Is that even possible in Glide?
AFAIK those are the only two ways to get even close to reproducible builds.
Are you checking your dependencies into your repository (we do this, it works very well).
If not, are you pinning specific commit hashes? Is that even possible in Glide?
AFAIK those are the only two ways to get even close to reproducible builds.
It's just a tad absurd when you're used to mature package managers in other languages.
Repo removal, renaming, or whatever, are still problems, for sure.
Today, dep populates vendor/ with dependencies, and works equally well whether you decide to commit them or not.
Bundler is lovely.
In other cases, 'npm update <package>' doesn't work and I have to do uninstall/install. Very common with typescript, for example.
I have better things to do with my time than watching the same crates being compiled multiple times.
In any case, I appreciate that Go at least supports binary packages, but Go isn't a language for me, given the type system decisions.
it work if you are working on a project, it does not if you are library author who rely on other dependencies.