- you build a library: thewesley
- it has no lockfile
- it has a prod dep: baby-yoda@~1.0.0
- you published [email protected] and tested it works well with [email protected]
- it’s Dec 30: you’re on your honeymoon
- it’s Dec 31: baby-yoda published incompatible [email protected]
- it’s Jan 1st: I install [email protected]
- it’s Jan 1st: I’m frustrated that thewesley is broken
- it’s Jan 2nd: you don’t know that I’m frustrated until I open an issue or you manually run an “npm install” or someone triggers a CI/Pull Request to work on your project that verifies it.
Created
December 30, 2019 12:53
-
-
Save lirantal/f30be60a34d85e3fd7370990b75cdb73 to your computer and use it in GitHub Desktop.
why-absence-of-lockfiles-doesnt-help-consumers.md
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment