Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
World desk5 min

How to Pin and Verify Dependency Versions in npm and Python Projects

Use npm ranges with a committed lockfile and npm ci; use Python project metadata for supported dependencies and pinned requirements files for repeatable environments.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For repeatable installs, keep dependency declarations separate from the record of what was actually resolved. In npm, commit both package.json and package-lock.json, then use npm ci in automation. In Python, describe supported dependencies in project metadata and use a pinned requirements file to recreate an application environment; add hashes when downloaded artifact identity matters.

What pinning does—and what it does not do

A dependency declaration can express which versions a project supports, while a lockfile or pinned requirements file records the versions selected for a particular installation. These serve different purposes: compatibility policy helps a reusable project work across suitable versions; an environment snapshot helps an application or deployment install a known set.

As an Amazon Associate I earn from qualifying purchases.

Exact version pins constrain resolution, but they do not prove that every operating system, processor architecture, runtime, optional dependency, or native build will behave identically. Reproduce and verify the environments your project actually supports.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Pin and verify dependencies in npm

Declare dependencies and create the lockfile

  1. Add dependencies using npm install <package>. By default, npm saves a semver range in package.json, rather than requiring that exact version forever. If you want an exact direct-dependency version in the manifest, use npm install --save-exact <package> or npm install -E <package>.

  2. Run npm install to resolve dependencies and create or update package-lock.json. The manifest expresses acceptable ranges; the lockfile records the resolved dependency tree and package metadata, including resolved locations and integrity values. npm describes the lockfile as recording the exact tree so subsequent installs can reproduce it despite intermediate dependency updates: npm package-lock.json documentation.

  3. Review and commit both files. A lockfile is useful only if the version-controlled copy is the one used by the team and automation. npm recommends committing it so installs can reproduce the recorded tree: npm package-lock.json documentation.

Use npm ci for a clean automated install

In CI or deployment, run npm ci from the project directory. It requires a lockfile, removes an existing node_modules, fails if package.json and the lockfile disagree, and does not rewrite either file. Those properties make it a check that automation is installing the committed dependency state, rather than silently updating it. See npm ci documentation.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If the lockfile was generated with options that change dependency-tree shape, such as --legacy-peer-deps or --install-links, use the same configuration for npm ci. A committed project .npmrc can preserve these settings. The npm documentation covers this requirement in its npm ci guidance.

Check the npm toolchain too

Lockfile format and behavior vary across npm generations. Check the package-lock reference against the npm version your project supports; the documentation page identifies npm 12.1.0 in its version selector. A successful locked install confirms consistency for that install context, not universal equivalence across different Node.js versions, platforms, or native build environments.

Pin and verify dependencies in Python

Keep project metadata distinct from an environment lock

Use project metadata—commonly pyproject.toml—to declare the dependencies a project needs and appropriate supported version bounds. This describes what the project supports; it is not necessarily a complete list of every transitive package selected in one environment. The Python Packaging User Guide cautions that exhaustive transitive lists and exact pins are generally better suited to requirements files than package metadata such as install_requires: Packaging User Guide: install_requires vs. requirements files.

Create a pinned environment requirements file

For an application or deployment that needs a specific environment, use a requirements file with exact pins, for example requests==2.32.0. Install it with:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

python -m pip install -r requirements.txt

pip defines pinning as using the == operator to require a specific package version: pip: Repeatable Installs. The example version above illustrates the syntax; select versions appropriate to your project rather than treating it as a recommendation.

To capture the packages currently installed in an environment, activate that environment and run:

python -m pip freeze > requirements.txt

pip freeze reports installed package versions and can capture both direct and transitive packages. Treat its output as an environment snapshot to review, not as a curated statement of the versions your project supports. The pip documentation describes freeze as a way to list installed packages: Packaging User Guide: installing packages using pip and virtual environments.

Install and inspect in the intended environment

  1. Create and activate a virtual environment for the project. Use the Python executable appropriate to your platform: the guide shows python3 on Unix-like systems and py on Windows. Follow its virtual-environment instructions.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  2. Install from the committed file with python -m pip install -r requirements.txt, using the same interpreter context as the application.

  3. Inspect the installed set with python -m pip freeze or python -m pip list and compare it with the requirements file. The environment and package listing commands are documented in the Packaging User Guide.

Add hashes when artifact identity matters

Exact pins identify versions; hashes can additionally verify that downloaded artifacts match approved files. pip’s hash-checking mode requires exact version matching and can help guard against index or certificate-chain compromise and changes to an artifact published under the same version. See pip secure installs and hash-checking mode.

Hash checking has a trade-off: it does not provide the availability benefits of a private package index or vendored libraries. A hash confirms an artifact against the expected digest; it cannot make that artifact available if the package source is unavailable.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to verify before relying on a lock

npm and Python: what the files actually guarantee

Question npm Python with pip
Where are project compatibility declarations? package.json expresses dependency ranges; --save-exact can save an exact direct dependency version. Project metadata such as pyproject.toml describes dependencies and supported bounds; it is not generally a full environment lock.
Where is the resolved environment recorded? package-lock.json records the resolved dependency tree and package metadata. A pinned requirements file can record exact versions, including transitive packages captured from an installed environment.
How do you install against that record? npm ci performs a clean install and errors on manifest-lock disagreement. python -m pip install -r requirements.txt installs the requirements supplied; hash-checking can add artifact verification.
What verifies artifact identity? The lockfile records integrity metadata for packages. Declared hashes are checked in pip hash-checking mode; exact pins are required.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.