Lock Files

Back to Dependency Pinning

Files that record the exact versions of all direct and transitive dependencies resolved during installation (package-lock.json, yarn.lock, Pipfile.lock, go.sum, Cargo.lock). Lock files must be committed to version control to ensure reproducible builds across environments.

supply-chain-security dependencies lock-files