mbien commented on PR #8034:
URL: https://github.com/apache/netbeans/pull/8034#issuecomment-2536413976

   IMO: I don't think it makes sense to maintain 14MB sig files over third 
party libs in our source code repo. The usefulness of sigs over dependencies is 
more of informational nature anyway since their API is not something we can 
influence. I don't have anything against them in principle - but a 14mb text 
file is a bit much in this particular case.
   
   Whether the 29 new dependencies for a Kubernetes deploy action are justified 
or not I don't know, since I don't see any cost/benefit analysis or discussion 
anywhere which compares other options. But there are essentially three likely 
outcomes: a) PR gets reverted and we regen the sigs or b) cost/benefit is 
justified and we turn sig tests off for that set of dependencies. c) we merge 
it as is
   
   I don't think we should merge this as is.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

For further information about the NetBeans mailing lists, visit:
https://cwiki.apache.org/confluence/display/NETBEANS/Mailing+lists

Reply via email to