Skip to content
Better HN
Top
Best
Ask
Show
New
Jobs
Search
⌘K
Package-lock.json pins only first-order dependencies
(opens in new tab)
(twitter.com)
2 points
mikehall314
4y ago
1 comments
Save
Share
1 comments
1 comments · 1 top-level
top
newest
oldest
metaloha
4y ago
Doesn't using `npm ci` instead of `npm install` keep transitive dependencies pinned as well?
1 more reply
j
/
k
navigate · click thread line to collapse