4 ms·
While the distinction of construct vs contract is subtle, improved tooling will eventually elevate the "construct" to a contract. semver needs to be combined w
by sramam 8y ago
While the distinction of construct vs contract is subtle, improved tooling will eventually elevate the "construct" to a contract.
semver needs to be combined with a package manager and strong version locking semantics for it to be useful.
Both npm and yarn in the node eco-system certainly provide this - with any remaining kinks are being ironed out fast.
Using micro-modules as dependencies is a rather pleasant experience in node/js - especially when the dependencies follow semver. This is even more true of popular modules, where authors take their versioning responsibility seriously.
I regularly use automated version updates (npm-check -u [1]/ npm audit --fix [2]). Coupled with good test coverage of my code, I've been really happy.
[1] https://www.npmjs.com/package/npm-check https://www.npmjs.com/package/npm-check
[2] https://docs.npmjs.com/getting-started/running-a-security-audit https://docs.npmjs.com/getting-started/running-a-security-au...