Hacker News new | past | comments | ask | show | jobs | submit login

> Caveats

> If you wish to lock down the specific bytes included in a package, for example to have 100% confidence in being able to reproduce a deployment or build, then you ought to check your dependencies into source control, or pursue some other mechanism that can verify contents rather than versions.

https://docs.npmjs.com/cli/shrinkwrap




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: