Without a deterministic build I don't know what I check in actually works across environment, or if the deployment artifact works.
Without a deterministic build I don't know what I check in actually works across environment, or if the deployment artifact works.
There's loads of ways to know what you are using without needing to strip mtime's from zip files.
Actually that's mostly a given in JS land.
Many bright minds worked hard for it to be this level of idiot-proof.
I may be a better idiot.
Weird that it didn't complain during building or installation.
Anyway I had one project where I couldn't use `async` `await`, because apparently this feature requires Babel 7, which in turn requires a version of node fresh enough to support generators.
This tends to happen, but it's rare to discover such an issue only after starting the application.
I use to have this concern, but it's really not an issue with modern package managers. Even without a checksum in a lock file (e.g. gem bundler), I haven't actually had a deployment break because of dependencies changes. The biggest issue is being blocked for a couple hours because a package repo went down.
Most of this is solved by using a self-hosted or 3rd party proxy package manager.