Hacker News new | ask | show | jobs
by panzi 37 days ago
Plus the lock file doesn't just contain the exact versions, it contains hashes. Making sure that you actually got the package in the exact same version.