Yarn vs. npm5 determinism
yarnpkg.com
yarnpkg.com
Particularly if you're storing important data using the name of a file type that, for the last few decades, has been something any Linux or Unix user can delete without significant consequence.
I guess the one thing to take away from this is that js tool authors and c tool authors don't talk to each other enough.
https://medium.com/@Rich_Harris/tree-shaking-versus-dead-cod...
Who wants to deal with keeping absolutely every developer and every build/production system on exactly the same version of Yarn?
1. The amount of noise in the lock file likely does matter for teams of any modest size
2. Yarn doesn't guarantee determinism for hoisting between different versions, but... in reality there's no reason to expect different behavior simply because there's a version difference.
The second point is pretty key, because it means yarn can deal with the issue through fairly standard means (like versioning, documentation, warnings, etc). Plus, most orgs already handle versioning and compatibility between tools in some form or other.
Finally, NPM 5 doesn't actually guarantee hoisting is deterministic between versions, they just have enough information that they COULD guarantee it. For all we know, NPM 6 will change the format of the file entirely... or perform new hoisting optimizations based on the lockfile that are incompatible with the logic in 5.
has-flag@^1.0.0: version "1.0.0" resolved "https://registry.yarnpkg.com/has-flag/-/has-flag-1.0.0.tgz#9...
supports-color@^3.2.3: version "3.2.3" resolved "https://registry.yarnpkg.com/supports-color/-/supports-color... dependencies: has-flag "^1.0.0"
{ "name": "react-example", "version": "1.0.0", "lockfileVersion": 1, "dependencies": { "has-flag": { "version": "1.0.0", "resolved": "https://registry.npmjs.org/has-flag/-/has-flag-1.0.0.tgz", "integrity": "sha1-nZ55MWXOAXoA8AQYxD+UKnsdEfo=" }, "supports-color": { "version": "3.2.3", "resolved": "https://registry.npmjs.org/supports-color/-/supports-color-3..., "integrity": "sha1-ZawFBLOVQXHYpklGsq48u4pfVPY=" } } }
Yarn file seems to have more not less info.