Current best practices for depencency management for registered packages

Not at all. See eg this issue; it is unfortunate that it was closed without a solution.

Also, you may be interested in

My impression is that the current setup is considered a collection of temporary measures, so no one feels like documenting it. The best source is this discussion, but it hard to find for newbies. I asked my questions because I noticed some PRs in the related code checking the Project.toml, and I was curious.

1 Like