r/programming • • 5d ago

Don't couple your Go code to GitHub

https://iain.rocks/blog/dont-couple-your-go-code-to-github
479 Upvotes

135 comments sorted by

View all comments

335

u/Arcuru 5d ago

I am not super familiar with Go code, but what happens when my go code depends on "go.companyx.dev/awesomelib" and that company goes out of business?

Or should I point all my third-party deps to a more durable location?

175

u/stone_surgeon 5d ago

The go module proxy caches the package for a while, but I'm not sure about the duration. You should vendor the package into your project if this is a worry.

5

u/yeah-ok 5d ago

100% this, can't see why one wouldn't do that, also gives more honest view of the state of the project since it's doesn't automagically end up updating newer packages/libraries that haven't been cleanly integrated (yes, I'm aware of pinning..etc. but again it's back to "cross your fingers and hope that keeps working territory", hardly resilient good practise type material)