easyPhone Screen

What is the purpose of `package-lock.json`?

51 views
01

Understand the problem

This question tests knowledge of dependency management specifics, crucial for reproducible builds.

npmdependenciespackage-lock.jsonversioning
02

Attempt it yourself

Sketch your approach before reading the solution — that's what interviews test.

Stuck? AI Nudge Available

Get a conceptual hint to guide your logic without spoiling the final implementation.

03

Study the solution

The solution is waiting

Give it an honest attempt first — then compare your thinking with the full walkthrough.

04

Read the code

Why two installs can differ without it
# package.json says: "lodash": "^4.17.0"
# Without a lockfile, these can resolve to different patches:
#   Monday  → lodash 4.17.20
#   Friday  → lodash 4.17.21
# With package-lock.json committed, both get the SAME version.

npm ci      # CI: install exactly the locked tree, fail if drifted
05

Join the discussion

Discussion (0)

Sign in to join the discussion.

No responses yet. Be the first to share what you think.