Compared. To. What? (Alternatively: "uh... yes?")
This is something like the third time that I've had to confront a comment alluding to the idea that having dependencies checked in to your repo means that updating them becomes, through some unspecified means, extremely difficult. And not just difficult, but intractably difficult. How exactly? Who knows—I've asked, but all I get are the same sort of continual allusions, as if it's some forgone conclusion on which there is common agreement, or it's a self-evident truth or something, but the actual thought process behind the remarks remain as impenetrable as the first time it was said. Please show your work. Please.
What precisely is the mechanism by which this this is supposed to happen and that forms the basis for your position? What two things precisely are you comparing to one another? Be specific. Don't be vague.
This conversation shouldn't be this exasperatingly difficult to have.
Manually checking all of them to even see what has updates available will take at least 10 to 20 minutes searching one by one. Likely up to several hours, even at 30 seconds per manual check.
The odds that laziness or tight schedules will take over and nobody ever actually does this are higher.
If one does actually do this, then they will be wasting 20 minutes regularly.
I don't know what you're referring to. The resolution up for debate is "Dependencies belong in version control". You seem to be having a totally different conversation (where you "manually copied and pasted things into your repo").
What "Dependencies belong in version control" means is:
- DO NOT add them to .gitignore.
- DO `git add` them just like any other code.
Updating things doesn't change; you update the packages that you depend on the same way you do if you aren't checking your dependencies in—e.g. by running `npm update` (or whatever).
Things like this SO thread seems to suggest manually copying dependencies is a somewhat common (bad ideaful) interpretation of the concept though:
https://softwareengineering.stackexchange.com/questions/3724...
"Why prefer a package manager over a library folder?" is a false dichotomy. Package managers are still responsible for managing packages—when your dependencies are checked into the repo, the package manager just operates on the packages that are already on disk instead of fetching them in a separate step and/or at the very last minute and being intertwined with the build process.