# Add \`package-lock.json\` to the node-red repo

**URL:** <https://discourse.nodered.org/t/add-package-lock-json-to-the-node-red-repo/3694>\
**Category:** Feature Requests\
**Created:** [4 October 2018 18:36 UTC](https://discourse.nodered.org/t/add-package-lock-json-to-the-node-red-repo/3694 "2018-10-04T18:36:29Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![bsatrom](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bsatrom/32/2973_2.png) [@bsatrom](https://discourse.nodered.org/u/bsatrom)\
**Post date:** [4 October 2018 18:36 UTC](https://discourse.nodered.org/t/add-package-lock-json-to-the-node-red-repo/3694/1 "2018-10-04T18:36:29Z")

</div>

I just cloned the `node-red` repo locally and noticed after running `npm install` that the `package-lock.json` has not been committed to master. It's [considered a good practice](https://github.com/npm/npm/blob/v5.0.0/doc/files/package-lock.json.md) to do this. Assuming you all have not previously decided NOT to add this file for a compelling reason, I am happy to submit a PR that adds this file.

Thanks!

Brandon

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [4 October 2018 19:03 UTC](https://discourse.nodered.org/t/add-package-lock-json-to-the-node-red-repo/3694/2 "2018-10-04T19:03:16Z")

</div>

Hi - one of the reasons we've avoided adding it in is because we have some dependencies where we _want_ npm to pick the latest available version of the extra node-red nodes the core pulls in: [https://github.com/node-red/node-red/blob/e03a0fffa9ea2b195d5acda5a8e918b148bce1b7/package.json#L63-L66](https://github.com/node-red/node-red/blob/e03a0fffa9ea2b195d5acda5a8e918b148bce1b7/package.json#L63-L66)

I believe if we introduce `package-lock.json` we'll lose that ability as it'll install the specific version in the lock file and not the latest that matches the semver in package.json - happy to be corrected if I'm wrong on it.

With the `dev` branch for 0.20, things get a more complicated as we now have 5 modules under the one repo - and the development process never runs `npm install` under each of those modules, so we don't get a package-lock file generated for them.

So it's something to look at, but not necessarily as simple as just checking one in.
