Official docs say it’s for

Packages that are only needed for local development and testing.

Umm, okay. Not 100% clear there. Some articles mention things like ESLint or Jest (k, I’m onboard there) but others mention Babel or WebPack. I get that you don’t need WebPack libraries to be loaded in the browser but how the hell do you bundle up your code without it? When you use npm ci or npm install you’ll get all dependencies but isn’t it good practice (in a CICD environment) to use --omit=dev or --only=prod?

  • BrianTheeBiscuiteer@lemmy.worldOP
    link
    fedilink
    arrow-up
    1
    ·
    10 months ago

    This isn’t exactly the case but yes, I would prefer to keep the dependency list as small as possible, mainly because I’m subject to security scans and I don’t want things to get held up because there’s a vulnerability in my linter.