Skip to content

Conversation

@dcodeIO
Copy link
Member

@dcodeIO dcodeIO commented Mar 14, 2020

This is basically #1168, but keeps the duplicate dependencies/devDependencies so we still support installing --prod from GH. Also upgraded upstream dependencies of our dependencies and uses my package-lock, which differs between OSes, as ground truth.

@dcodeIO dcodeIO requested a review from MaxGraey March 14, 2020 10:10
@MaxGraey
Copy link
Member

But I'm not sure is it necessary support npm i AssemblyScript/assemblyscript today? When we have daily night builds?

@dcodeIO
Copy link
Member Author

dcodeIO commented Mar 14, 2020

This again makes me wonder a bit about the usefulness of committing a package-lock. While it prevents unintended breaking changes, it also has the downside that if there is a vulnerable package the exact version of the package becomes pinned, even though just reinstalling dependencies would fix this. Like, ts-node depends on minimist ~1.2.0, which would upgrade just fine to 1.2.5, but is prevented by package-lock?!

@dcodeIO
Copy link
Member Author

dcodeIO commented Mar 14, 2020

But I'm not sure is it necessary support npm i AssemblyScript/assemblyscript today? When we have daily night builds?

It's certainly exotic, yet is easy to support and might be useful if someone wants to install a specific PR from a forked branch for testing that isn't merged yet. Let's say you fork, make changes, perhaps not even a PR, then I could install that exact forked branch via GH for a quick test run.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants