https://bugzilla.redhat.com/show_bug.cgi?id=2415364



--- Comment #5 from Ben Beasley <[email protected]> ---
Relaying Fabio Valentini’s opinion from the Fedora Rust channel on Matrix,

> and in general, I think vendoring is "reasonable" if you end up needing to 
> package > 20 new dependencies

(But I’ll add that conversely, the more dependencies you vendor that are
already separately packaged, the more burden of reviewing the contents and
licensing of your dependencies, and perhaps patching some of them, falls solely
on you rather than being shared with other maintainers.)


-- 
You are receiving this mail because:
You are always notified about changes to this product and component
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2415364

Report this comment as SPAM: 
https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-spam&short_desc=Report%20of%20Bug%202415364%23c5

-- 
_______________________________________________
package-review mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to