How it works
package.json holds the project's name, version and scripts (such as dev, build and test), plus two lists: dependencies needed to run and devDependencies needed only to build and test. Each entry names a version range such as ^2.1.0, which allows newer compatible releases, so two installs a few months apart could pull in different code.
The lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) fixes that by recording the exact version and checksum of every package in the whole tree. It belongs in Git, and CI should install with npm ci or its equivalent so every machine gets identical code. Deleting the lockfile to fix a problem usually just swaps it for a different, unknown one.
Related terms
More in Dev workflow and DevOps
Packages