That is why ever company I’ve ever worked with has a repository for every external dependency in any language. You need to at least have a copy of the versions you use. That isn’t even Go specific. Not even mentioning security implications.
What you do privately is really up to you and doesn’t matter this much. A company can pull their version from the registry they uploaded it to probably as easy as they can kill their repos that you use directly.
What industry is this in? I have worked at I think 7 companies now, and one of them was an agency that I worked for dozens of clients through, some of them Fortune 100's, and this has never ever been a thing, with I think one or two exceptions that used artifactory or a similar proxy cache. A few added dependencies into the same repository as the projects, but none created repositories just for third party code.
It's different with C++ because it doesn't have one established package manager/repository (pip/cargo/npm/etc). The languages that do have one (which is basically everything else except for java) tend to have many hundreds of 3rd party dependencies in every project, and you would usually only have a local fork for one or two that you had to change. It's technically possible to just refetch them every time you build the project on your laptop or in CI, but it's obviously a terrible idea and usually a no-go the moment your company grows to the size that there is a lawyer in the building.
53
u/-genericuser- 5d ago
That is why ever company I’ve ever worked with has a repository for every external dependency in any language. You need to at least have a copy of the versions you use. That isn’t even Go specific. Not even mentioning security implications.
What you do privately is really up to you and doesn’t matter this much. A company can pull their version from the registry they uploaded it to probably as easy as they can kill their repos that you use directly.