cor*_*lok 8 javascript webpack yarnpkg
我在yarn.lock中看到一个包的3个不同版本,例如:
angular@1.6:
version "1.6.10"
resolved "https://registry.yarnpkg.com/angular/-/angular-1.6.10.tgz#eed3080a34d29d0f681ff119b18ce294e3f74826"
integrity sha512-PCZ5/hVdvPQiYyH0VwsPjrErPHRcITnaXxhksceOXgtJeesKHLA7KDu4X/yvcAi+1zdGgGF+9pDxkJvghXI9Wg==
angular@>=1.4.0, angular@^1.0.8:
version "1.7.7"
resolved "https://registry.yarnpkg.com/angular/-/angular-1.7.7.tgz#26bd87693deadcbd5944610a7a0463fc79a18803"
integrity sha512-MH3JEGd8y/EkNCKJ8EV6Ch0j9X0rZTta/QVIDpBWaIdfh85/e5KO8+ZKgvWIb02MQuiS20pDFmMFlv4ZaLcLWg==
angular@~1.2.0:
version "1.2.32"
resolved "https://registry.yarnpkg.com/angular/-/angular-1.2.32.tgz#df52625a5167919931418dda3a9208b9f5fa3db4"
integrity sha1-31JiWlFnkZkxQY3aOpIIufX6PbQ=
Run Code Online (Sandbox Code Playgroud)
这是否意味着最终的捆绑包包含所有捆绑包,否则webpack如何知道要选择哪个版本?社区中解决该问题的最佳实践是什么?我知道--flat选项,但是有成千上万个软件包,我需要一段时间才能为每个选择一个。
Sta*_*lfi 13
要调查依赖项安装了多少次以及哪些包依赖于它(递归),请运行:yarn why <package-name>。
查看是否可以升级(或降级)某些包,以确保包中的所有依赖项都使用相同版本的 Angular。
例如:yarn why execa:
yarn why v1.22.5
[1/4] Why do we have the module "execa"...?
[2/4] Initialising dependency graph...
[3/4] Finding dependency...
[4/4] Calculating file sizes...
=> Found "execa@4.0.3"
info Has been hoisted to "execa"
info Reasons this module exists
- "workspace-aggregator-c3b3be41-6d00-4635-98a6-d5373b215152" depends on it
- Specified in "devDependencies"
- Hoisted from "_project_#pretty-quick#execa"
- Hoisted from "_project_#@tahini#nc#execa"
- Hoisted from "_project_#execa"
- Hoisted from "_project_#jest#@jest#core#jest-changed-files#execa"
info Disk size without dependencies: "136KB"
info Disk size with unique dependencies: "520KB"
info Disk size with transitive dependencies: "736KB"
info Number of shared dependencies: 19
=> Found "lint-staged#execa@2.1.0"
info This module exists because "_project_#lint-staged" depends on it.
info Disk size without dependencies: "76KB"
info Disk size with unique dependencies: "400KB"
info Disk size with transitive dependencies: "616KB"
info Number of shared dependencies: 19
=> Found "sane#execa@1.0.0"
info This module exists because "_project_#jest-haste-map#sane" depends on it.
info Disk size without dependencies: "40KB"
info Disk size with unique dependencies: "328KB"
info Disk size with transitive dependencies: "524KB"
info Number of shared dependencies: 16
=> Found "create-folder-structure#execa@2.1.0"
info Reasons this module exists
- "_project_#create-folder-structure#pretty-quick" depends on it
- Hoisted from "_project_#create-folder-structure#pretty-quick#execa"
info Disk size without dependencies: "76KB"
info Disk size with unique dependencies: "400KB"
info Disk size with transitive dependencies: "616KB"
info Number of shared dependencies: 19
=> Found "term-size#execa@0.7.0"
info This module exists because "_project_#nodemon#update-notifier#boxen#term-size" depends on it.
info Disk size without dependencies: "36KB"
info Disk size with unique dependencies: "324KB"
info Disk size with transitive dependencies: "520KB"
info Number of shared dependencies: 16
Run Code Online (Sandbox Code Playgroud)
笔记:
Qua*_*ion 10
正如另一个答案提到的,这些额外的版本可能是由于开发依赖性而导致的,并且实际上可能不会出现在您发布的 JS 包中。我建议使用捆绑分析器来确保您的应用程序仅附带所有大型模块(如 Angular)的单一版本。
另一件需要注意的事情是,yarn v1.x 并没有积极优化和去重复模块版本。如果您希望yarn.lock文件中的包数量最少,您需要yarn-deduplicate在添加或升级yarn包后立即执行实用程序npm模块,即:
npm install -g yarn-deduplicate
yarn-deduplicate yarn.lock
Run Code Online (Sandbox Code Playgroud)
该实用程序将分析和优化yarn.lock 文件,以便用最少的模块集满足所有版本依赖性。在上面的示例中,运行yarn-deduplicate yarn.lock可能会将yarn.lock中的前2个角度版本合并为单个版本:
angular@>=1.4.0, angular@^1.0.8, angular@1.6:
version "1.6.10"
resolved "https://registry.yarnpkg.com/angular/-/angular-1.6.10.tgz#eed3080a34d29d0f681ff119b18ce294e3f74826"
integrity sha512-PCZ5/hVdvPQiYyH0VwsPjrErPHRcITnaXxhksceOXgtJeesKHLA7KDu4X/yvcAi+1zdGgGF+9pDxkJvghXI9Wg==
Run Code Online (Sandbox Code Playgroud)
这种优化/重复数据删除内置于yarn v2.x中,因此我建议升级yarn,这样您就不必担心项目的后续问题。