I suppose? You’re either reviewing your dependencies or you’re not; I don’t think it matters much whether the unreviewed code comes in via a commit to your git repo or via a package manager. Once you’ve decided to either vendor or fork, that it matches your upstream becomes much less important — what matters is it works for your project. Either approach definitely comes with tradeoffs, that’s for sure; I only fork when I need to float a commit, and I prefer to maintain an artifactory if high availability is required.
In hindsight, I question the wisdom of my decision to respond to this thread at 2 am my time 😅. Thanks for being nice even though my responses were borderline incoherent.
I suppose? You’re either reviewing your dependencies or you’re not; I don’t think it matters much whether the unreviewed code comes in via a commit to your git repo or via a package manager. Once you’ve decided to either vendor or fork, that it matches your upstream becomes much less important — what matters is it works for your project. Either approach definitely comes with tradeoffs, that’s for sure; I only fork when I need to float a commit, and I prefer to maintain an artifactory if high availability is required.
I meant the users of your project.
In hindsight, I question the wisdom of my decision to respond to this thread at 2 am my time 😅. Thanks for being nice even though my responses were borderline incoherent.
No worries, it’s 3am here right now 😁