@f0x @trysdyn yeah that's the one
given the alternative is manually managing package-lock.json for an enterprise react app, using a different package manager, or the obnoxious pattern of adding extra direct dependencies (that didn't seem to work nearly as well as maven where it's also an unmaintainable mess) it's really bewildering that hasn't been upstreamed
@f0x @trysdyn i forget what exactly we were doing
but we couldn't figure it out without using yarn