4 ms·
This sounds more like a fix for an issue that should not exist in the first place. Why is npm ignoring the lock file to begin with? Why not publish and respect
by smartinspereira 7y ago
This sounds more like a fix for an issue that should not exist in the first place. Why is npm ignoring the lock file to begin with? Why not publish and respect it on install?
- ailideex 7y agoIf your package only works with specific versions you should put those versions in package.json - if the versions in package.json is correct then what specific versions within those bounds someone uses is ... well ... unrelated to your package.
- syspec 7y agoIt can blow up your bundle size if everyone has patch version mismatch . That's probably the only reason I can think of. In theory semver should help with this, but humans decide the semver version and it's not always possible to know the effects of a change so they may mark it as patch, but it breaks something and you get this sceanrion
- paulddraper 7y agoIt's a consequence of modularization, and it's not at all unique to Node.js. (Although Node.js has hyper-modularization, so the situation is more pronounced.) Ruby gem has lock files, Python pip has lock files. I wish everyday that apt/dpkg had lock files. The balance is between permissive versions (small install size) and pinned versions (reproducibility). Some situations call for one, some call for the other.
- j88439h84 7y agoBut doesn't Node give each module its own deps? Python can't do this because it doesn't support multiple versions of the same dep.