10,244 karma · joined March 3, 2015
Um, yes. That is fairly obvious, and really should not be surprising to anyone doing research with LLMs. But we don't need anything really novel here, we already have VMs, containers, firewalls, airgaps, etc.
And both of those concerns can be addressed by using an internal/private registry that mirrors the packages you need.
But in any event, your original question was to elaborate on why vendoring is inconvenient. Whether or not the benefits are worth the inconvenience is a different question, to which IMHO the answer is "it depends". Sometimes it is, and sometimes it isn't.
That sounds like it's inconvenient to me.
The biggest problem isn't (usually) disk space, or network bandwidth, it is that git operations slow down as the size of the repo grows. And it means that cloning or pulling the repo takes longer, which can be especially problematic for CI.
> Recursive dependencies have the same issues whether you vend them or not.
Package managers usually handle resolving recursive/transitive dependencies for you. Some have support for vendoring dependencies, but not all do. In theory, you could have similar tooling for vendoring dependencies, but in practice that often isn't the case.
It bloats your repo, both with the actual code, and the large diffs when you update it.
You have to manually track new versions, without something to tell you if new versions are available, or if your version has known security vulnerabilities.
If the dependency has it's own dependencies, you have to vendor those too recursively. And if multiple dependencies have the same transitive dependency, it is up to you to deduplicate them, and make sure you have a version compatible with all dependents.
Etc.
And even on my desktop, where battery life doesn't matter, I wouldn't mind my CPU needing less cooling.
I say this as someone who will probably never own a mac.
- A boat cast a shadow, but the mooring rope didn't
- A bench leg was out of perspective, and didn't touch the ground
- In a pile of logs,the ends were sharpened in an unnatural way[0]
- In several there seems to be an inconsistent contrast between something that looks more dirty, worn, weathered, etc. while the surroundings are more clean and smooth.
Some also feel off in a way that I can't really articulate.
[0]: I think the relationship to the prompt was interesting here, the prompt actually asked for a stack of wooden fence posts, but they were really thick for fence posts, and looked more like firewood with a sharpened point. Interestingly, the prompt included the phrase "without excessive sharpening" which I think meant increasing the sharpness of the image, but I wonder if the AI interpreted as referring to the sharpness of the fence posts.
This avoids the dreaded undefined behavior, but it can still be pretty bad. For example, accessing a record that has been freed and re-used could leak sensitive information from one user to another. Granted that kind of bug is possible with any memory safe language, but this pattern is probably more like to be used in goose than languages with automated memory management.
Not just in terms of service costs, but in time and complexity. In many cases building out that complexity is complicated and difficult. And sometimes the functionality you need isn't supported in the regions you use.