Hacker News new | ask | show | jobs
by Soremwar 1616 days ago
Hence why developers always recommend to use immutable sources when importing modules
1 comments

The web isn't immutable.
"Immutable" in the sense that packages can't be taken down or modified by authors

If you wanna take it a step further, you can always opt in to that lock file with various degrees of strictness as you yourself mentioned