npm dependencies pull in different versions of the same package

Viewed 126

Wondering if someone can help me understand why this is happening. I have two npm packages that use tar-fs@2.1.0 but that package pulls in different versions of tar-stream. It is defined in the package.json as "tar-stream": "^2.0.0" but they resolve to different patch versions when running npm install. Reading about caret-ranges I'm not seeing anything to explain this.

I tried deleting the node_modules and lock file, running npm update tar-stream, and running npm install --package-lock-only to update the lock file based on 'package.json'. Any help is appreciated.

$ npm ls tar-stream
project@1.2.0 /Users/akerr/Documents/GitHub/project
├─┬ chrome-aws-lambda@5.3.0
│ └─┬ lambdafs@2.0.0
│   └─┬ tar-fs@2.1.0
│     └── tar-stream@2.1.3
└─┬ puppeteer-core@5.3.0
  └─┬ tar-fs@2.1.0
    └── tar-stream@2.1.4
0 Answers
Related