Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Since nobody else answers your question:

> Do they just mean package.json here?

Yes, most likely. A package-lock.json always specifies an exact version with hash and not a "version X or newer".



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: