chore: add back package-lock.json and enable dependabot#939
chore: add back package-lock.json and enable dependabot#939aduh95 merged 1 commit intonodejs:mainfrom
package-lock.json and enable dependabot#939Conversation
Codecov ReportAll modified and coverable lines are covered by tests ✅
Additional details and impacted files@@ Coverage Diff @@
## main #939 +/- ##
=======================================
Coverage 80.15% 80.15%
=======================================
Files 39 39
Lines 4635 4635
=======================================
Hits 3715 3715
Misses 920 920 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
|
@nodejs/node-core-utils wdyt? |
|
No objections from me. I prefer a higher chance of discovering unintended breaking changes in dependencies to the reproducibility of the dev env but I can live with it. |
Has this ever happened btw? I've tried looking for other projects that one would more likely install globally rather than locally (create-react-app, heroku, pm2), they all seem to use a lock file – although I didn't spend much time looking for it. BTW I'm not sure being meant to be installed globally change much, packages that are installed locally also do not use the upstream lockfile. |
|
In this project, I don't know. It has already happened in other projects I maintain. |
targos
left a comment
There was a problem hiding this comment.
RSLGTM on the dependabot config
It was removed based of #311, however having a reproducible dev env is good actually.