Business
Jobs
  • About Us
  • Solutions
    • Job Postings
      Post your job and receive qualified candidates in 48h.
    • Candidate Assessments
      500+ technical and psychological tests, plus anti-fraud.
    • Headhunting
      Tailor-made executive search from start to finish.
    • Payroll + EOR
      Payroll dispersal and EOR across 15+ LATAM countries.
  • Pricing
  • Jobs

0

234
Views
Why are there extra required dependencies in package-lock.json?

React recently released a new version that has breaking changes to the TypeScript typings (Can be read about here). Packages that require "@types/react": "*" target this new version automatically and cause my project to break.

I thought that I'd go to the projects that have this style of requirement and either ask them to change the dependency to optional or remove it. Then I thought I'd be more proactive and make a pull request to make the change myself and get some experience contributing to open source.

However, I have yet to find where this change would be made in the project. I have looked through the first 5 packages that have this problem and have yet to find where @types/react is required.

As an example, in my package-lock.json file the listing for @types/react-redux shows that it requires @types/react: "*"

@types/react-redux entry in package-lock.json file

So I go to the npm page for @types/react-redux and follow the link to the github page (I also verified that I'm on the most recent version). I would expect the required packages to be found in the package.json file there, and they all are except @types/react.

contents of package.json for @types/react-redux

We are having a heck of a time trying to get our project working again after the changes to React being automatically pulled in because of these required "*" versions of @types/react.

Can anyone help educate me as to where this is coming from so that I could either make pull requests for these projects or ask the maintainers to make the change?

about 4 years ago · Juan Pablo Isaza
1 answers
Answer question

0

It's because index.d.ts imports react, but since package.json does not contain an explicit dependency on @types/react, DefinitelyTyped adds it automatically to the generated package.json of the npm bundle using information provided by the TypeScript compiler.

To pin the dependency version, simply add it explicitly to package.json, e.g.:


{
    "private": true,
    "dependencies": {
        "@types/hoist-non-react-statics": "^3.3.0",
        "@types/react": "16",
        "hoist-non-react-statics": "^3.3.0",
        "redux": "^4.0.0"
    }
}

("@types/react": "16" is just an example - use a version or version range that fits). For a real example, see this merged pull request that introduces a similar change.

about 4 years ago · Juan Pablo Isaza Report
Answer question
Find remote jobs

Discover the new way to find a job!

Top jobs
Top job categories
Business
Post vacancy Pricing Sales
Legal
Terms and conditions Privacy policy
© 2026 PeakU Inc. All Rights Reserved.
Andres GPT
Show me some job opportunities
There's an error!