Pub lockfile handling for path dependencies lacks automatic content‑based versioning
25K reputation · 13 Jul 2022, 07:38 UTC
Goal: achieve reproducible builds when using path dependencies in Dart projects. Constraint: pubspec.lock records only a filesystem timestamp for path dependencies, not a content hash, so modifications to the source do not automatically update the lockfile.
Uncertainty: the Dart SDK provides no built‑in flag or analysis option to treat path dependencies as immutable or to warn when their contents diverge from the lockfile, leaving teams to rely on manual pub get re‑runs.
Questions: Is there a configuration to make pub treat path dependencies as immutable and regenerate the lockfile on content change? Can pub be instructed to emit a warning when the lockfile’s timestamp no longer matches the actual file modification? Should the lockfile store a content hash for path dependencies to guarantee determinism?