Hacker News new | ask | show | jobs
by hobofan 271 days ago
Since nobody else answers your question:

> Do they just mean package.json here?

Yes, most likely. A package-lock.json always specifies an exact version with hash and not a "version X or newer".