4 ms·
npm does maintain a lockfile for you by default since npm 5, if that's what you mean. There really is no reason to be encountering surprise sub-dependency chan
by allover 8y ago
npm does maintain a lockfile for you by default since npm 5, if that's what you mean.
There really is no reason to be encountering surprise sub-dependency changes with npm.
- megaman22 8y agoHappens all the time when package.json defaults to foo: "^1.2.3", and some bozo does breaking changes in 1.2.5.
- danabramov 8y agoIf you have a package lock, even caret in package.json won't automatically install it.
- allover 8y ago> Happens all the time when package.json defaults to foo: "^1.2.3", and some bozo does breaking changes in 1.2.5. No it doesn't. Since npm 5, npm is lockfile-by-default, you don't get updates unless you ask for them. Whether one particular package correctly respects semver is irrelevant.