Skip to content

Reuse Less Software

wiki.alopex.li
2 pointshaeseong1 comment
On HN

Comments

I'm not following this argument. I think there's no real reliability difference between having SHA256-verified dependencies by lock file and vendoring the same dependencies into the codebase. If there's a concern with crates.io availability partial local mirroring is possible.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.