Open post Martin Auswöger @ausi@mastodon.social · 6mo ago Replying to @brendt@phpc.social <p>I was reading this blog post about how package managers are evil. I don't really agree on the "evil" part because package managers do solve a problem that would be very hard to deal with manually. That being said, I was curious enough to do a little experiment.</p><p><a href="https://stitcher.io/blog/dependency-hygiene" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="ellipsis">stitcher.io/blog/dependency-hy</span><span class="invisible">giene</span></a></p> @brendt Couldn’t you add something like this to the composer.json of your project in order to opt-out of pulling that package? "replace": { "symfony/polyfill-mbstring": "*" }
Open post Martin Auswöger @ausi@mastodon.social · 6mo ago Replying to @brendt@phpc.social @ausi Yes, I added that to the blog post :) It's still a very crude solution to a deeper problem though, since this needs to happen on the project level, and the developer needs to actually think about it. Nevertheless, very good to mention @brendt Agreed. And yes, we should probably be more stricter with our dependencies :)