logoalt Hacker News

nananana9today at 4:23 PM1 replyview on HN

You should 100% track package-lock.json, and I'll go a step further and say you should most likely track node_modules too.


Replies

necovektoday at 8:33 PM

If the underlying infrastructure does not provide reproducible builds, I'd suggest you should instead fix that.