Tool reports same versions as updates

#22 · open · 3 comments

View on GitHub ↗

gaitat

I am using `salita -o` and I don't want to use the `--ignore-pegged` flag as I do want pegged packages to be reported if there are updates. But I get these types of updates which I don't think are valid: ```Development Dependencies: Changed: browser-sync from 2.26.3 to ^2.26.3 Changed: http-server from 0.11.1 to ^0.11.1 Changed: husky from 1.3.1 to ^1.3.1 ``` My package.json does include ``` "devDependencies": { "browser-sync": "2.26.3", "http-server": "0.11.1", "husky": "1.3.1" } ```

Comments

ljharb

The intention is to upgrade them to use the semver range; if they're pegged on purpose they should ideally have an explicit `=` there - otherwise it just looks like you forgot the `^`. Why are they pegged at all if you want updates? Pegging packages is for indicating they violate semver or have a bug; avoiding unintentional updates can only be addressed with a lockfile.

gaitat

I find that the lock file doesn't work for me. On different machines I get different lock files. Maybe I have not mastered them. I would like to use pegged libraries in order for my entire team to have the same version of the software and the dependencies. That does not mean that I don't want library updates.

ljharb

That’s a separate issue and doesn’t change that without a lockfile, pegging offers you no guarantees. Only a lockfile guarantees that.