4 ms·
> But package lock is ignored for all users of your npm. Only root package’s lock file has effect. This makes it useless in most cases. But package-lock is int
by allover 7y ago
> But package lock is ignored for all users of your npm. Only root package’s lock file has effect. This makes it useless in most cases.
But package-lock is intended to be used at the project level. i.e. lock all package versions in the current project or app.
That isn't "useless in most cases", it solves specifically the case it is meant to solve.
> It’s even more useless if you think that production apps are built very often as tagged docker images = are reproducible by design.
But you're stuffed if you need to rebuild the docker image later, or for example, go back to an old commit/release, create a 'support' branch to retrofit a change and build a new image. You want repeatability all the way down.