Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You could but everybody uses version pinning in production, right?


People who are serious about reproducible builds host their own repos. Most people probably don’t know the difference between ^1.0.1 and ~1.0.1


Thanks for making me look that up!


If only npm's version pinning actually version pinned without idiotic subrules. package-lock.json is just one massive lie.


What do you mean?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: