Open kirillzyusko opened 2 hours ago
Triggered auto assignment to @grgia (AutoAssignerAppLibraryReview
), see https://stackoverflowteams.com/c/expensify/questions/17737 for more details.
Once these questions are answered, start a thread in #engineering-chat, ping the @app_deployers
group, and call for a vote to accept the new library. Once the vote is complete, update this issue with the outcome and procede accordingly. Here is a sample post:
Hey @app_deployers,
There is a request to add a new library to App that we need to consider. Please look at this GH and then vote :+1: or :-1: on accepting this new library or not.
GH_LINK
In order to properly evaluate if a new library can be added to
package.json
, please fill out this request form. It will be automatically assigned someone from our review team that will go through and vet the library.In order to add any new production dependency, it must be approved by the App Deployer team. They will evaluate the library and decide if it's something we want to move forward with or if other alternatives should be explored.
Note: This is only for production dependencies. While we don't want people to add packages to dev-dependencies willy-nilly, we recognize that there isn't as great of a need there to secure them.
Name of library:
Details