logoalt Hacker News

pjmlptoday at 10:28 AM1 replyview on HN

> Every package manager has its own lockfile format. Gemfile.lock, package-lock.json, yarn.lock, Cargo.lock, poetry.lock, composer.lock, go.sum. They all record roughly the same information: which packages were installed, at what versions, with what checksums, from where.

Nope, Java and .NET ecosystem don't use them.


Replies

homebrewertoday at 10:38 AM

One can easily opt-in with modern dotnet.

https://devblogs.microsoft.com/dotnet/enable-repeatable-pack...

show 1 reply