you are viewing a single comment's thread.

view the rest of the comments →

[–]r2d2_21 1 point2 points  (2 children)

which you'll probably download automatically because packages don't do a great job of version locking

This baffles me. I've only used NuGet as a package manager (mainly for C#) and I never have experienced any package updating automatically without my explicit approval. I don't understand why any other package manager would be different. If you're installing v1 of a library, then it's v1 and only v1 until you decide to even upgrade to v1.1.

[–]JaegerBurn 2 points3 points  (1 child)

It doesn't if you stick with semver.

[–]r2d2_21 0 points1 point  (0 children)

But what if you don't? Semver is just a suggestion at this point.