logoalt Hacker News

williamjacksonyesterday at 5:12 PM1 replyview on HN

Thank you for expressing my thoughts as well. The article seems to be full of contradictory “advice”.

Use a dependency cooldown, okay … but don’t commit your lockfile so you are always running the latest transitive deps? That’s nuts.


Replies

Uvixyesterday at 7:16 PM

Depends on the package manager. With some you'll get the oldest transitive deps that meet all dependency requirements, not the newest.