logoalt Hacker News

kjmrtoday at 7:15 AM1 replyview on HN

“Removing upper version bounds is important when publishing libraries.”

That makes total sense! The article however was written as someone creating websites, not libraries. And when I consume dependencies in my web project, I do want those upper bounds to prevent breaking changes (assuming the dependencies respect SemVer of course).

Thanks for pointing out that config, I’ve updated the article.


Replies

euiqtoday at 10:36 AM

`uv.lock` pins exact versions (and hashes) of your dependencies.

show 1 reply