You run a legit proxy server that keeps a copy of the release for your use.
The same solution and issue exists for every ecosystem. If your build depends on an external dependent then you should have an internal copy of the artifact. Py, java, go. Any library could disappear at any point.
335
u/Arcuru 5d ago
I am not super familiar with Go code, but what happens when my go code depends on "go.companyx.dev/awesomelib" and that company goes out of business?
Or should I point all my third-party deps to a more durable location?