A bit more precise, would be to hash lockfile instead of package.json dependencies.
A bit more precise, would be to hash lockfile instead of package.json dependencies.