4 ms·
The main problem with your approach is that you have full control over your dependencies but no control over their dependencies, unless you're inspecting every
by Merad 7y ago
The main problem with your approach is that you have full control over your dependencies but no control over their dependencies, unless you're inspecting every single package in your dependency graph to make sure that every one of them targets specific versions in its package.json. Realistically, using package-lock.json and npm ci is the only way to ensure that everyone on your team and your deployments are all working off of the same node_modules folder.
- deleted 7y ago[deleted]