What would make a package manager different from any other tool? It's a dependency like any other, it only makes sense to have it locked like any other.

Comments