In the simplest terms, the tilde matches the most recent minor version (the middle number). ~1.2.3 will match all 1.2.x versions but will miss 1.3.0.
The caret, on the other hand, is more relaxed. It will update you to the most recent major version (the first number). ^1.2.3 will match any 1.x.x release including 1.3.0, but will hold off on 2.0.0.
npm ll - shows dependencies tree structure npm info any_node_module - shows full info about any_node_module
Keep track of your currently available packages: e.g., npm ls --depth=0. read more...
See if any of your packages have become unused or irrelevant: depcheck. read more...
Why:
You may include an unused library in your code and increase the production bundle size. Find unused dependencies and get rid of them.
Why:
More usage mostly means more contributors, which usually means better maintenance, and all of these result in quickly discovered bugs and quickly developed fixes.
Why:
Having loads of contributors won't be as effective if maintainers don't merge fixes and patches quickly enough.
Why:
Dependency updates sometimes contain breaking changes. Always check their release notes when updates show up. Update your dependencies one by one, that makes troubleshooting easier if anything goes wrong. Use a cool tool such as npm-check-updates.
Check to see if the package has known security vulnerabilities with, e.g., Snyk.
Content type
Image
Digest
Size
352.9 MB
Last updated
over 7 years ago
docker pull llsoft/node