Installing and managing libraries.
WHAT THEY DO
Resolve dependencies Install specified versions Record what was installed Provide a registry of available packages
WHAT EVERY ECOSYSTEM HAS
One or more, with differing conventions.
WHAT TO ALWAYS COMMIT
The declaration of what you require The lock file recording exactly what was installed
WHY THE LOCK FILE
It guarantees identical versions on every machine and in production.
WHAT TO NEVER COMMIT
The installed packages.
WHAT VERSION RANGES MEAN
Accepting updates within stated limits.
WHAT THAT RISKS
A dependency changing behaviour without you doing anything.
WHAT THE LOCK FILE PREVENTS
Exactly that.
WHAT TO DISTINGUISH
Runtime dependencies from development-only ones.
WHY
Development tooling should not reach production.
WHAT TO AUDIT
Known vulnerabilities Unused packages Duplicate versions of the same package
WHAT TO BE CAREFUL WITH
Packages with names resembling popular ones Packages executing code on installation Very deep dependency trees
WHAT TO ESTABLISH IN A PROJECT
One package manager, used consistently.