Hacker News new | past | comments | ask | show | jobs | submit login

They don't need to pin it directly.

They only need to "npm ci" (based on package-lock.json) instead of "npm install" (based on package.json) within the Docker container to get a fully reproducible build.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: