logoalt Hacker News

roca10/02/20240 repliesview on HN

Oh, you mean vendoring. Yes, you can do that, but there is no easy support for keeping those vendored dependencies in sync with upstream. And if you want really nice things like notifications when those dependencies have security updates that you need to apply --- forget it.