> There is little difference...

+1 to this. Also add nimblefiles to that, and then if you're using other build 
systems, like makefiles, or gradle, this witch hunting quickly becomes 
impractical. And then if we add --confirm flag, it is all-or-nothing, so once 
you need one staticExec, you're under the "risk" again. To conclude, I see 
absolutely no point in such measures, because one way or another you must trust 
your dependencies, be it staticExec, runtimeExec, or 
runtimeDoTheLogicTheDependencyIsSupposedToDoInTheFirstPlace.

Reply via email to