Consider not pinning dependencies
envgap__lint-staged__lint-staged-1653
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- In a clean container the reported failure did not reproduce, or the known fix did not make the project run.
02 / ENVIRONMENT RECIPE
- Base commit
54c9bea2c7e3cd1562c33d3125c5fe5a450ca333- Manifest
package.json- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
lint-staged/lint-staged #1653 · read the original issue
Hi 👋 🙂
First of all, thanks to everyone for all the hard work on this project; it's an excellent dev tool.
I would like to call out this move to pin dependencies and discuss it further, if you don't mind. I feel like this is a dangerous path. You are a big name in JS dev-tools and others may follow your lead here. If everyone goes around pinning dependencies, it could make node_modules very heavy with lots of duplicated packages all using slightly different versions. It also completely nullifies the whole point of SemVer: Let's say that one of your dependencies discovers an issue, your users now cannot upgrade without waiting for you to do a release or resort to using overrides.
I believe the issue with the recent supply chain attacks is obviously a concerning one but it's something that package managers should, and are, resolving. Both Yarn and pnpm have implemented cool-down periods that can be added to ensure packages have had time to be scanned by the community before being installed into production. This is a first step and I'm sure there will be more, and hopefully npm will also do something too.
I don't think you should feel the responsibility is on you to protect your users from your dependencies; developers know how the package resolution system works and it's on them to protect themselves.
If you keep your dependencies to a sensible range (i.e. don't release an update requiring latest minor/patch versions as soon as they are released and only when _you_ need them) then this isn't something you need to worry about. _You_ are _not_ the cause for someone to get a dodgy version of `chalk`.
I hope that helps. And thanks again!
Will.
_Originally posted by @will-stone in https://github.com/lint-staged/lint-staged/issues/1626#issuecomment-3323860222_
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]