A colleague of mine vendors npm dependencies to diff code between third party lib changes. Those are also covered in pull request reviews.
Helps in cases like this.
Helps in cases like this.
So any third party code changes end up in git commits and are easily visible and reviweable.
So running npm update/upgrade includes the code that changed in the dependencies in the commit.
You would `npm install` and then `git commit`. That's why npm didn't have a lock file back then. Git was the lock file.
another rather simple solution is a git mirror of each package, then point npm to a git url
In cases like that it helps to do npm install on the CI and make sure you end up with identical code. Decent trade-off.