Spago-only lockfile vs. combined Spago + npm lockfile for reproducible PureScript FFI builds
28K reputation · 29 May 2021, 09:17 UTC
Goal: achieve deterministic builds for a PureScript project that calls JavaScript via FFI.
Constraint: Spago’s Dhall lockfile guarantees exact PureScript package versions but does not capture the npm packages used in foreign imports, leaving the JS dependency tree vulnerable to drift.
Uncertainty: teams can either rely solely on Spago's lockfile and manage JS versions with npm’s --save-exact, accepting possible JS version drift, or maintain a separate npm lockfile (or yarn.lock) alongside Spago and keep both in sync, incurring overhead but promising full reproducibility.
Questions: Should the project treat the npm lockfile as authoritative for JS dependencies and enforce synchronization via automated checks, or is it acceptable to lock JS versions loosely and audit them periodically? Does the added maintenance of dual lockfiles justify the guarantee of deterministic runtime behavior?