> Disk is cheap

If I want to upgrade the disk on my MacBook Pro, I need to buy a new MacBook Pro with a larger disk. If I want to upgrade the disk on my work laptop, I’m SOL.

> Ensuring that diffs to updated dependencies remain within a vendor folder is trivial.

It’s not obvious to me how putting the dependencies in a vendor folder solves the diff problem. Does every code host allow you to hide diffs to certain directories?

And what’s the advantageous scenario for vendored dependencies? Is it just when the mod proxy and the upstream code host go down at the same time?

> If I want to upgrade the disk on my MacBook Pro, I need to buy a new MacBook Pro with a larger disk

Is this a significant risk in reality? MBPs today come with a minimum of 1TB of storage. Even 5 years ago I think the minimum was 256 GB. This is more than large enough for all but the hugest repositories, even with vendored dependencies. And you can always plug in external SSDs or HDDs or connect to a network server. Let’s talk about actual problems, shall we?

> And what’s the advantageous scenario for vendored dependencies? Is it just when the mod proxy and the upstream code host go down at the same time?

This is a useful homework assignment. Ask your favorite LLM or consult some respected release engineering books. Also consult your local AppSec and infosec teams.