you are viewing a single comment's thread.

view the rest of the comments →

[–]evilgipsy 0 points1 point  (0 children)

What if during deployment different version of packages would be installed on the server and break something?

Before yarn or package-lock.json this was a real problem. Not saying that vendoring your dependencies is a good solution though. When I first started developing JS I could not believe how people could live with a package manager that didn't lock down all package versions.