logoalt Hacker News

hesyiahlast Sunday at 1:59 PM1 replyview on HN

Instead of committing the binary, I highly recommend using a .tool-versions file (if you use asdf or mise) or a Dockerfile with a pinned version.


Replies

supermattlast Sunday at 2:02 PM

What is the downside to committing the binary? Immunity to supply chain attacks and a faster build time?

show 1 reply