I can’t believe npm still sucks after 10 years. Week doesn’t go by I have to nuke node_modules and occasionally the lock as well. It’s junk as far as I’m concerned, but I just happen to know what the problem is every time.
I can’t believe npm still sucks after 10 years. Week doesn’t go by I have to nuke node_modules and occasionally the lock as well. It’s junk as far as I’m concerned, but I just happen to know what the problem is every time.
I am genuinely curious what are the specific issues which necessitate deleting all modules? Colleagues across operating systems with native modules? Old node versions?
Why? Because installing the dependencies they specify and running babel (implicitly at the latest version) does not have reproducible results. It's that simple. package-lock.json is specifically supposed to help with this, but in some cases, it just doesn't, and it's entirely possible, and common(!) to have two sets of package.json files produce differing package-lock.json files.
They even have a warning below that can still occur even if you already have the dependencies specified above installed:
> If you see an error message saying “You have mistakenly installed the babel package”, you might have missed the previous step. Perform it in the same folder, and then try again.
[1]: https://reactjs.org/docs/add-react-to-a-website.html
[2]: https://reactjs.org/docs/add-react-to-a-website.html#add-jsx...
Locally I just delete it and use yarn for all my commands, and they can use NPM for their commands.
It doesn't make much of a difference, not actually sure what the problem is.
Nobody would even know whether you're using yarn or NPM if you don't commit a lockfile I suppose
Just like no one would think of letting their developers choose whether they want to bundle their code using either Webpack or Rollup, the package manager should really be enforced at the project level, whether you choose Yarn or npm.
But I've been doing this for years and so far haven't ran into it
I really don't have the mental energy to fight with people over package managers -- it's just not worth it.
> your colleagues and you may have slightly different behaviors in development (on top of desync'd dependency trees).
Yarn and NPM both take a "package.json" and install the dependencies so that you can import them though.If I have "express" in my package.json and do "npm install" or "yarn install" -- the functional outcome is (and always should be) the same
Unless you're using some package-manager specific behavior so that it only works properly or relies on particularities from either yarn/npm/pnpm whatnot, I'm not sure I understand how this could cause problems
But also, you're the lead maintainer of Yarn and I'm just some schmuk who's been on the consuming end for the last many years. I reckon you've got a fair bit more clue here than I do.
Commit your lockfiles. Their whole point is to reduce the risk of dependencies silently breaking your build.
If you don't run tests in your production environment (and most people don't), then you need to commit a lockfile and use it when deploying.