Track 3rd party libs used in the dist package
- Dominant language
- Java
- Stars
- 14.1k
- Forks
- 3.8k
- Avg merge
- 2d 58m
- Merged PRs (30d)
- 233
Description
### Description
It would be great to at least somehow track the 3rd party deps in a way that they need changes to the PR itself if new ones gets added - which will drag attention toward them and could possibly improve the situation.
### Motivation
It seems like there are quite a few versions of the same lib in the distribution build - these might have landed via transitive deps and most likely without being considered.
Contributor guide
Research direction
The issue names no files, tests, or build entry points. Start by locating how the distribution package and its transitive dependencies are assembled, then determine how third-party libraries are currently declared. Done should mean the distribution dependencies are explicitly tracked and adding one requires a visible PR change.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- build-system
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100