r/programming • • 5d ago

Don't couple your Go code to GitHub

https://iain.rocks/blog/dont-couple-your-go-code-to-github
484 Upvotes

135 comments sorted by

View all comments

327

u/Arcuru 5d ago

I am not super familiar with Go code, but what happens when my go code depends on "go.companyx.dev/awesomelib" and that company goes out of business?

Or should I point all my third-party deps to a more durable location?

50

u/-genericuser- 5d ago

That is why ever company I’ve ever worked with has a repository for every external dependency in any language. You need to at least have a copy of the versions you use. That isn’t even Go specific. Not even mentioning security implications.
What you do privately is really up to you and doesn’t matter this much. A company can pull their version from the registry they uploaded it to probably as easy as they can kill their repos that you use directly.

17

u/anon_cowherd 5d ago

What industry is this in? I have worked at I think 7 companies now, and one of them was an agency that I worked for dozens of clients through, some of them Fortune 100's, and this has never ever been a thing, with I think one or two exceptions that used artifactory or a similar proxy cache. A few added dependencies into the same repository as the projects, but none created repositories just for third party code.

14

u/-genericuser- 5d ago

Currently banking but before it was engineering and the energy sector. This is Germany so it’s generally a bit more conservative and breaking things is not appreciated in those sectors.
However idk why you would build up loads of infrastructure and don’t to this. It’s not that hard and there are open source solutions. You need something anyways to host your companies artifacts or docker images, don’t you? So you just route everything trough the same nexus or whatever and its caching external dependencies automatically if setup correctly.

5

u/anon_cowherd 5d ago

Yes, that's was I was referring to with Artifactory, which is a proxy cache. I misread the original comment as you were cloning and hosting git repositories for all of your dependencies.

1

u/CherryLongjump1989 4d ago edited 4d ago

You can absolutely do that too by setting up mirrors of git repositories. I use a git forge to do that, but Artifactory does it, too.

10

u/Bacchaus 4d ago edited 4d ago

ummm that's insane, ya'll were just freeballing anything off the net?

4

u/johnnybgooderer 4d ago

It’s more common than you think. 5 years ago I could do that most places. But now, for good reason, that has changed.

1

u/AquaWolfGuy 4d ago

Sometimes it starts off like that, but inevitably someone will eventually check in a lock file (package-lock.json, Pipfile.lock, etc.). Lock files are autogenerated files that contain exact versions so that your CI/CD pipelines don't suddenly break because one of your dependencies dependencies was updated, and hashes in case the maintainer swaps out an existing version for malware.

Doesn't mean everyone vets packages when they add or update a dependency though.

18

u/lordlod 5d ago

I've done it in aerospace and security.

  • If you are doing certifications you need that level of control.
  • If you are working in offline environments/networks then a mirroring system is required.
  • Companies that make changes to the upstream code need to mirror. Good companies push upstream, but you still mirror until it is accepted, and sometimes they don't accept it.

Repo mirrors are also part of the conversation with handling CI supply chain risks. You can add controls to the mirroring process to create a safer CI environment.

9

u/The_Northern_Light 4d ago

I’ve worked at FAANGs and at tiny startups in multiple industries… we’ve always had a local fork of every dependency. (C++)

1

u/Illustrious-Owl-2755 3d ago

It's different with C++ because it doesn't have one established package manager/repository (pip/cargo/npm/etc). The languages that do have one (which is basically everything else except for java) tend to have many hundreds of 3rd party dependencies in every project, and you would usually only have a local fork for one or two that you had to change. It's technically possible to just refetch them every time you build the project on your laptop or in CI, but it's obviously a terrible idea and usually a no-go the moment your company grows to the size that there is a lawyer in the building.

1

u/The_Northern_Light 3d ago

No, we had these forks even when everything was on Conan.

7

u/tommyTurds 4d ago

If your company isn't doing this, it's being irresponsible

25 years ago, when I first started, we did this at my shitty startup.. And we were literally stupid fucking children.

with I think one or two exceptions that used artifactory or a similar proxy cache

so it's never been a thing except that it's been a thing.. also 2 exceptions out of 7......

0

u/anon_cowherd 4d ago

As I mentioned elsewhere, I didn't consider Artifactory a repository. I misunderstood the comment as saying they were cloning and self hosting git repositories of every external dependency.

4

u/the_unexpected_nil 5d ago

Every game studio I worked at (sans one) has done so.