DEV Community

Discussion on: When not to use package-lock.json

Collapse
 
robogeek profile image
David Herron

You can always use exact version number dependencies in package.json. Package-lock.json is unnecessary.

Collapse
 
drkn profile image
Maciej Dragan

Your "exact version number dependencies" have other dependencies which most likely are not "exact version number dependencies", so case described by @stereobooster still applies. You will most likely get different packages in time when you use npm install on your project without package-lock file, and your project may break because of that. I agree it's a pain to maintain it but sometimes there is no other way.