← All tasks
javascriptlint-staged/lint-staged #1653Not a task: not reproduced

Consider not pinning dependencies

envgap__lint-staged__lint-staged-1653

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • In a clean container the reported failure did not reproduce, or the known fix did not make the project run.

02 / ENVIRONMENT RECIPE

Base commit
54c9bea2c7e3cd1562c33d3125c5fe5a450ca333
Manifest
package.json
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

lint-staged/lint-staged #1653 · read the original issue
Hi 👋 🙂 



First of all, thanks to everyone for all the hard work on this project; it's an excellent dev tool.



I would like to call out this move to pin dependencies and discuss it further, if you don't mind. I feel like this is a dangerous path. You are a big name in JS dev-tools and others may follow your lead here. If everyone goes around pinning dependencies, it could make node_modules very heavy with lots of duplicated packages all using slightly different versions. It also completely nullifies the whole point of SemVer: Let's say that one of your dependencies discovers an issue, your users now cannot upgrade without waiting for you to do a release or resort to using overrides.



I believe the issue with the recent supply chain attacks is obviously a concerning one but it's something that package managers should, and are, resolving. Both Yarn and pnpm have implemented cool-down periods that can be added to ensure packages have had time to be scanned by the community before being installed into production. This is a first step and I'm sure there will be more, and hopefully npm will also do something too.



I don't think you should feel the responsibility is on you to protect your users from your dependencies; developers know how the package resolution system works and it's on them to protect themselves.



If you keep your dependencies to a sensible range (i.e. don't release an update requiring latest minor/patch versions as soon as they are released and only when _you_ need them) then this isn't something you need to worry about. _You_ are _not_ the cause for someone to get a dodgy version of `chalk`.



I hope that helps. And thanks again!



Will.



_Originally posted by @will-stone in https://github.com/lint-staged/lint-staged/issues/1626#issuecomment-3323860222_

            
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]