logoalt Hacker News

JimDabell06/24/20251 replyview on HN

If the lock file is missing the only sensible thing to do is require human intervention. Either it’s the unusual case of somebody initialising a project but never syncing it, or something has gone seriously wrong – with potential security implications. The upside to automating this is negligible and the downside is large.


Replies

guappa06/24/2025

? It has always been the case that if you don't specify a version, the latest is implied.

show 1 reply