Dependency management
- Keep all the dependencies outside the repository.
- Avoid using suspicious, unknown dependencies as they may introduce vulnerabilities.
Go dependencies
- Use go mod as dependency manager.
- Run
export GO111MODULE=on
to enablego mod
. - Run
go mod tidy
before sending any changes. - Use only official releases, avoid using master versions.
JavaScript dependencies
- Use npm as package manager.
- Run
npm ci
after checking out the repository to install dependencies. - Dependabot Preview updates packages by creating pull requests for
the new releases of used packages. Its pull requests are marked with
area/dependency
label. - Update
package-lock.json
before sending any changes.
Copyright 2019 The Kubernetes Dashboard Authors
当前内容版权归 Kubernetes 或其关联方所有,如需对内容或内容相关联开源项目进行关注与资助,请访问 Kubernetes .