Empresas
Empleos
  • Sobre nosotros
  • Soluciones
    • Publicación de vacantes
      Publica tu vacante y recibe candidatos calificados en 48h.
    • Evaluación de candidatos
      500+ pruebas técnicas y psicológicas, más anti-fraude.
    • Headhunting
      Búsqueda ejecutiva a la medida de principio a fin.
    • Nómina + EOR
      Dispersión de nómina y EOR en más de 15 países de LATAM.
  • Precios
  • Empleos

0

233
Vistas
Why are there extra required dependencies in package-lock.json?

React recently released a new version that has breaking changes to the TypeScript typings (Can be read about here). Packages that require "@types/react": "*" target this new version automatically and cause my project to break.

I thought that I'd go to the projects that have this style of requirement and either ask them to change the dependency to optional or remove it. Then I thought I'd be more proactive and make a pull request to make the change myself and get some experience contributing to open source.

However, I have yet to find where this change would be made in the project. I have looked through the first 5 packages that have this problem and have yet to find where @types/react is required.

As an example, in my package-lock.json file the listing for @types/react-redux shows that it requires @types/react: "*"

@types/react-redux entry in package-lock.json file

So I go to the npm page for @types/react-redux and follow the link to the github page (I also verified that I'm on the most recent version). I would expect the required packages to be found in the package.json file there, and they all are except @types/react.

contents of package.json for @types/react-redux

We are having a heck of a time trying to get our project working again after the changes to React being automatically pulled in because of these required "*" versions of @types/react.

Can anyone help educate me as to where this is coming from so that I could either make pull requests for these projects or ask the maintainers to make the change?

about 4 years ago · Juan Pablo Isaza
1 Respuestas
Responde la pregunta

0

It's because index.d.ts imports react, but since package.json does not contain an explicit dependency on @types/react, DefinitelyTyped adds it automatically to the generated package.json of the npm bundle using information provided by the TypeScript compiler.

To pin the dependency version, simply add it explicitly to package.json, e.g.:


{
    "private": true,
    "dependencies": {
        "@types/hoist-non-react-statics": "^3.3.0",
        "@types/react": "16",
        "hoist-non-react-statics": "^3.3.0",
        "redux": "^4.0.0"
    }
}

("@types/react": "16" is just an example - use a version or version range that fits). For a real example, see this merged pull request that introduces a similar change.

about 4 years ago · Juan Pablo Isaza Denunciar
Responde la pregunta
Encuentra empleos remotos

¡Descubre la nueva forma de encontrar empleo!

Top de empleos
Top categorías de empleo
Empresas
Publicar vacante Precios Comercial
Legal
Términos y condiciones Política de privacidad
© 2026 PeakU Inc. All Rights Reserved.
Andres GPT
Recomiéndame algunas ofertas
Necesito ayuda