Intern / FresherNode.js

What is the difference between package.json and package-lock.json?

Quick answer

package.json lists your project's dependencies with allowed version ranges, while package-lock.json records the exact versions that were installed so every machine gets an identical dependency tree.

In package.json, a range such as ^4.18.0 allows any compatible 4.x update. The lock file pins the exact resolved version and the integrity hash of every package, including nested dependencies. Commit both files, and use npm ci in CI and production builds: it installs exactly what the lock file says and fails if the two files disagree, while npm install may update the lock file.

Also know the difference between dependencies (needed at runtime) and devDependencies (build and test tools), and run npm audit regularly to check for known vulnerabilities.