So the lockfile is a superset, but never a subset?
So it basically is an SBOM then but just sometimes has extra dependencies?
Superset of dependencies, but often a subset of info per depedency.
Superset of dependencies, but often a subset of info per depedency.