>
Resolve your deps once, at build time, and you're done.I have ... rarely had this experience.
Every go package manager has found new and frankly fascinating ways to lead me into a corner where I think I have committed and pushed working code, but which causes highly-visible CI barfing.
I should add as an aside: I've done two tours of duty as a Cloud Foundry Buildpacks maintainer. Everyone's package system sucks, but some suck a lot less.
* Maven is basically sane if used with levelled starters. Otherwise it's a preview of fighting the Many-Tentacled Ones of the Deeply Nested Dependency Graph using nothing but a dull butter knife held upside-down.
* Gradle is the worst allergic reaction to XML in history.
* NPM used to have amazing bugs and missing features but has laboriously, slowly improved.
* Python is about whether you hit the sweet spot of the particular packaging system you use.
* PHP is a mess, unless you use Composer, in which case you're still stuck with the weird reality that PHP's package system is really a mix of in-process modules which need to be compiled and slabs of plain old PHP.
* .NET Core had what seems like a deliberate policy to come up with the most confusing naming and versioning scheme humanly possible and was wildly successful at doing so. Oh, and no canonical reference for versions. None. Apparently this improved but it was hell on earth.
* Golang. A new package manager every ten minutes. A different vendoring model, different assembly model, different bugs, every damn week.
Only Bundler is basically sane. We hit lots of corner cases but for the 20/80 cases it essentially worked.