<turbo-stream action="append" target="posts_list"><template>    <div class="postbit" id="359614" data-post-id="359614">
  <section>
    <div class="post-wrap">


					<div class="post-header">
		        <div class="user-avatar">
		          <img alt="lud" src="https://forum.elixirforum.com/user_avatar/forum.elixirforum.com/lud/120/14382_2.png" width="120" height="120" />
		        </div>
					
						<div class="user-details">
		          <div class="user-name">
		            <h3>
                  lud
                  </h3>
		          </div>
						
						</div>
					
					</div>

	        <div class="thread-main">
	            <div class="post-body" data-turbo="false">
								<p>Oh alright, yeah that’s a pretty common use case actually.</p>
<p>Thank you!</p>
<p>I’m not sure how that solves the “library A has a locked version of B but dev boxes for apps using A pull another version of B” though.</p> 
	            </div>

	            <div class="base-line">
	                <div class="thread-counters">
	                    <span class="thread-count count-likes js-likers-trigger" title="Likes" data-post-id="359614" data-batch-url="/posts/batch_likers">
                        0
                      </span>
                      <!-- <span class="thread-count js-solved-indicator" title="Marked as solution"></span> -->
	                </div>
	                <div class="go-to-post">
	                  <a title="Go to post" alt="Go to post" href="https://forum.elixirforum.com/t/thoughts-on-mix-lock-in-libraries-packages/35392/12">Post #11</a>
	                </div>
	            </div>
              <div id="likers-container-359614" 
                   class="likers-container"
                   data-first-post="false"
                   data-batch-url="/posts/batch_likers">
                   <div class="likers-placeholder" 
                     data-likers-post-id="359614"
                     data-batch-url="/posts/batch_likers">
                  <div class="post-likers"></div>
                </div>
              </div>
	        </div>
			

    </div>

    <div class="triangle-top-right type-standard-post cat-standard-post" title="Post #11"></div>
  </section>
</div>
    <div class="postbit" id="359618" data-post-id="359618">
  <section>
    <div class="post-wrap">


					<div class="post-header">
		        <div class="user-avatar">
		          <img alt="benwilson512" src="https://forum.elixirforum.com/user_avatar/forum.elixirforum.com/benwilson512/120/1457_2.png" width="120" height="120" />
		        </div>
					
						<div class="user-details">
		          <div class="user-name">
		            <h3>
                  benwilson512
                  </h3>
		          </div>
						
			          <div class="user-title">
									<span>Author of Craft GraphQL APIs in Elixir with Absinthe</span>
			          </div>
						</div>
					
					</div>

	        <div class="thread-main">
	            <div class="post-body" data-turbo="false">
								<p>Well normally that is solved by simply having <code>mix.lock</code> checked in, and then everyone gets the same deps. BUT that isn’t reliable if someone can check in a <code>mix.exs</code> with an out of sync <code>mix.lock</code>. Then, the next dev to pull down the library code will <code>mix deps.get</code> and get a new lock file.</p>
<p>So it’s really the combination of this together:</p>
<ol>
<li>Check in <code>mix.lock</code> so that deps are specified precisely and repeatably.</li>
<li>Use <code>--check-locked</code> in the CI to detect if the <code>mix.exs</code> file has drifted from the lockfile.</li>
</ol> 
	            </div>

	            <div class="base-line">
	                <div class="thread-counters">
	                    <span class="thread-count count-likes js-likers-trigger" title="Likes" data-post-id="359618" data-batch-url="/posts/batch_likers">
                        1
                      </span>
                      <!-- <span class="thread-count js-solved-indicator" title="Marked as solution"></span> -->
	                </div>
	                <div class="go-to-post">
	                  <a title="Go to post" alt="Go to post" href="https://forum.elixirforum.com/t/thoughts-on-mix-lock-in-libraries-packages/35392/13">Post #12</a>
	                </div>
	            </div>
              <div id="likers-container-359618" 
                   class="likers-container"
                   data-first-post="false"
                   data-batch-url="/posts/batch_likers">
                   <div class="likers-placeholder" 
                     data-likers-post-id="359618"
                     data-batch-url="/posts/batch_likers">
                  <div class="post-likers"></div>
                </div>
              </div>
	        </div>
			

    </div>

    <div class="triangle-top-right type-standard-post cat-standard-post" title="Post #12"></div>
  </section>
</div>
    <div class="postbit" id="359621" data-post-id="359621">
  <section>
    <div class="post-wrap">


					<div class="post-header">
		        <div class="user-avatar">
		          <img alt="lud" src="https://forum.elixirforum.com/user_avatar/forum.elixirforum.com/lud/120/14382_2.png" width="120" height="120" />
		        </div>
					
						<div class="user-details">
		          <div class="user-name">
		            <h3>
                  lud
                  </h3>
		          </div>
						
						</div>
					
					</div>

	        <div class="thread-main">
	            <div class="post-body" data-turbo="false">
								<p>I was referring to this:</p>
<aside class="quote no-group" data-username="mudasobwa" data-post="1" data-topic="35392">
<div class="title">
<div class="quote-controls"></div>
<img alt="" width="24" height="24" src="https://forum.elixirforum.com/user_avatar/forum.elixirforum.com/mudasobwa/48/5298_2.png" class="avatar"> mudasobwa:</div>
<blockquote>
<p>Consider the library <code>A</code> that depends on another library <code>B</code>. <code>B</code> occasionally introduces a breaking change in the minor updates. Even if <code>A</code> library has nightly builds turned on, it continues to be green because in <code>mix.lock</code> there is a previous version of <code>B</code>. All the projects, depending on <code>A</code> get broken, because they ignore <code>A</code>’s <code>mix.lock</code>.</p>
</blockquote>
</aside>
<p>I understand now why using <code>--check-locked</code> is interesting (actually I just added it to my own CIs) but I don’t see how it changes the need to try to build after deleting the <code>mix.lock</code> to see if everything is fine.</p>
<p>Sorry I may be too tired today to understand all of it.</p> 
	            </div>

	            <div class="base-line">
	                <div class="thread-counters">
	                    <span class="thread-count count-likes js-likers-trigger" title="Likes" data-post-id="359621" data-batch-url="/posts/batch_likers">
                        0
                      </span>
                      <!-- <span class="thread-count js-solved-indicator" title="Marked as solution"></span> -->
	                </div>
	                <div class="go-to-post">
	                  <a title="Go to post" alt="Go to post" href="https://forum.elixirforum.com/t/thoughts-on-mix-lock-in-libraries-packages/35392/14">Post #13</a>
	                </div>
	            </div>
              <div id="likers-container-359621" 
                   class="likers-container"
                   data-first-post="false"
                   data-batch-url="/posts/batch_likers">
                   <div class="likers-placeholder" 
                     data-likers-post-id="359621"
                     data-batch-url="/posts/batch_likers">
                  <div class="post-likers"></div>
                </div>
              </div>
	        </div>
			

    </div>

    <div class="triangle-top-right type-standard-post cat-standard-post" title="Post #13"></div>
  </section>
</div>
    <div class="postbit" id="359635" data-post-id="359635">
  <section>
    <div class="post-wrap">


					<div class="post-header">
		        <div class="user-avatar">
		          <img alt="benwilson512" src="https://forum.elixirforum.com/user_avatar/forum.elixirforum.com/benwilson512/120/1457_2.png" width="120" height="120" />
		        </div>
					
						<div class="user-details">
		          <div class="user-name">
		            <h3>
                  benwilson512
                  </h3>
		          </div>
						
			          <div class="user-title">
									<span>Author of Craft GraphQL APIs in Elixir with Absinthe</span>
			          </div>
						</div>
					
					</div>

	        <div class="thread-main">
	            <div class="post-body" data-turbo="false">
								<p>Oh ya I still think that the advice of having a CI task which deletes <code>mix.lock</code> and then tries to build / test is a great idea <em>for libraries</em>.</p>
<p>That said, I probably wouldn’t put it as a requirement for merging a PR. That is to say, if someone is trying to contribute to my library, I do expect the library to build and the tests to pass at the versions locked in the lock file. I want to <em>know</em> if maybe there’s some release out there which is going to require changes in my library, but that could be completely unrelated to the work of the contributor, and it isn’t reasonable to force them to solve that problem just because some dependency out there has a new version.</p>
<p>I would probably only run that additional task on <code>main</code>, so that I (and other contributors) can see that there is some maintenance work to be done to make sure it builds on the latest dep versions.</p> 
	            </div>

	            <div class="base-line">
	                <div class="thread-counters">
	                    <span class="thread-count count-likes js-likers-trigger" title="Likes" data-post-id="359635" data-batch-url="/posts/batch_likers">
                        3
                      </span>
                      <!-- <span class="thread-count js-solved-indicator" title="Marked as solution"></span> -->
	                </div>
	                <div class="go-to-post">
	                  <a title="Go to post" alt="Go to post" href="https://forum.elixirforum.com/t/thoughts-on-mix-lock-in-libraries-packages/35392/15">Post #14</a>
	                </div>
	            </div>
              <div id="likers-container-359635" 
                   class="likers-container"
                   data-first-post="false"
                   data-batch-url="/posts/batch_likers">
                   <div class="likers-placeholder" 
                     data-likers-post-id="359635"
                     data-batch-url="/posts/batch_likers">
                  <div class="post-likers"></div>
                </div>
              </div>
	        </div>
			

    </div>

    <div class="triangle-top-right type-standard-post cat-standard-post" title="Post #14"></div>
  </section>
</div>
    <div class="postbit" id="359648" data-post-id="359648">
  <section>
    <div class="post-wrap">


					<div class="post-header">
		        <div class="user-avatar">
		          <img alt="LostKobrakai" src="https://forum.elixirforum.com/user_avatar/forum.elixirforum.com/LostKobrakai/120/3072_2.png" width="120" height="120" />
		        </div>
					
						<div class="user-details">
		          <div class="user-name">
		            <h3>
                  LostKobrakai
                  </h3>
		          </div>
						
						</div>
					
					</div>

	        <div class="thread-main">
	            <div class="post-body" data-turbo="false">
								<aside class="quote no-group" data-username="benwilson512" data-post="15" data-topic="35392">
<div class="title">
<div class="quote-controls"></div>
<img alt="" width="24" height="24" src="https://forum.elixirforum.com/user_avatar/forum.elixirforum.com/benwilson512/48/1457_2.png" class="avatar"> benwilson512:</div>
<blockquote>
<p>I would probably only run that additional task on <code>main</code>, so that I (and other contributors) can see that there is some maintenance work to be done to make sure it builds on the latest dep versions.</p>
</blockquote>
</aside>
<p>I’d even argue that such a test is most useful when run regularly (e.g. nightly) and not run coupled to developer activity. It’ll be far more likely to catch issues that way if the intention is to catch them before users do.</p> 
	            </div>

	            <div class="base-line">
	                <div class="thread-counters">
	                    <span class="thread-count count-likes js-likers-trigger" title="Likes" data-post-id="359648" data-batch-url="/posts/batch_likers">
                        1
                      </span>
                      <!-- <span class="thread-count js-solved-indicator" title="Marked as solution"></span> -->
	                </div>
	                <div class="go-to-post">
	                  <a title="Go to post" alt="Go to post" href="https://forum.elixirforum.com/t/thoughts-on-mix-lock-in-libraries-packages/35392/16">Post #15</a>
	                </div>
	            </div>
              <div id="likers-container-359648" 
                   class="likers-container"
                   data-first-post="false"
                   data-batch-url="/posts/batch_likers">
                   <div class="likers-placeholder" 
                     data-likers-post-id="359648"
                     data-batch-url="/posts/batch_likers">
                  <div class="post-likers"></div>
                </div>
              </div>
	        </div>
			

    </div>

    <div class="triangle-top-right type-standard-post cat-standard-post" title="Post #15"></div>
  </section>
</div>
    <div class="postbit" id="359653" data-post-id="359653">
  <section>
    <div class="post-wrap">


					<div class="post-header">
		        <div class="user-avatar">
		          <img alt="fmcgeough" src="https://forum.elixirforum.com/user_avatar/forum.elixirforum.com/fmcgeough/120/4100_2.png" width="120" height="120" />
		        </div>
					
						<div class="user-details">
		          <div class="user-name">
		            <h3>
                  fmcgeough
                  </h3>
		          </div>
						
						</div>
					
					</div>

	        <div class="thread-main">
	            <div class="post-body" data-turbo="false">
								<p>This may make perfect sense. I think if I wanted to enforce <code>--check-locked</code> on my open source library I’d put notes about it in CONˇRIBUTING.md (and CHANGELOG.md) and ask that the person making the PR check-in the modified mix.lock file.</p>
<p>I use <a href="https://github.com/mtrudel/elixir-ci-actions/blob/main/.github/workflows/test.yml" rel="noopener nofollow ugc">Mat Trudel’s github actions</a> for my open source libraries. This just uses <code>mix deps.get</code>.</p>
<p>When I work for a company I’ve added <code>--check-locked</code> for the applications CI. It’s helped reduce confusion and made engineers more aware of what’s going on.</p> 
	            </div>

	            <div class="base-line">
	                <div class="thread-counters">
	                    <span class="thread-count count-likes js-likers-trigger" title="Likes" data-post-id="359653" data-batch-url="/posts/batch_likers">
                        0
                      </span>
                      <!-- <span class="thread-count js-solved-indicator" title="Marked as solution"></span> -->
	                </div>
	                <div class="go-to-post">
	                  <a title="Go to post" alt="Go to post" href="https://forum.elixirforum.com/t/thoughts-on-mix-lock-in-libraries-packages/35392/17">Post #16</a>
	                </div>
	            </div>
              <div id="likers-container-359653" 
                   class="likers-container"
                   data-first-post="false"
                   data-batch-url="/posts/batch_likers">
                   <div class="likers-placeholder" 
                     data-likers-post-id="359653"
                     data-batch-url="/posts/batch_likers">
                  <div class="post-likers"></div>
                </div>
              </div>
	        </div>
			

    </div>

    <div class="triangle-top-right type-last-post cat-last-post" title="Last post!"></div>
  </section>
</div>
</template></turbo-stream><turbo-stream action="replace" target="load-more-container"><template><div id="load-more-container" class="load-more-container">
    <span class="all-loaded">— All posts loaded —</span>
</div></template></turbo-stream>