Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> 1- Maintaining a mirror of dependencies can be a non-trivial overhead. In this app that I was working on, the previous devs had forked some gems on github, and then added that specific github repo to the requirements. But they did not do it for every dependency, probably they did not have time/resources to do that.

You've precisely identified the trade-off. You basically have three options. You can

1. Maintain a local repo of your dependencies (high effort)

2. No dependencies, include everything as 'first-class' code (lower upfront effort, but v. messy)

3. Rely on third-party repos (easiest, riskiest)



Yes I agree, yours is a very good summary of the main alternatives at play. They all have pros and cons as you have rightly noted.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: