Conversation

When the left-pad debacle happened, I feared that people would conclude “dependencies are bad”. (Instead of the logical conclusion, which is “don’t allow dependencies to be deleted from package registries.”) That prediction turned out to be true. :(
13
86
It means having a direct dependency on Git for fetching sources is problematic. Even if it ends up providing the option of a secure hash, it's not going to be consistently adopted and using this for verification in the first place is a bit crazy due to the order it does things.
1
Replying to
That's why I said it's an increasingly bad idea to depend on it. It doesn't make sense to be building infrastructure today that depends on sha1 and has no real migration plan away from it. Creating a dependency on Git revisions or signed commits / tags today isn't a good plan.
1
Show replies