react-scan 0.5.x floats react-grab and react-doctor on the "latest" dist-tag, making resolutions non-reproducible#468
Description
[email protected] declares two of its dependencies with the latest dist-tag rather than a semver range:
// [email protected]
"dependencies": {
"react-doctor": "latest",
"react-grab": "latest"
}
react-grab has been latest since 0.5.5, and react-doctor was added the same way in 0.5.7.
Because latest is a moving target, the resolved transitive tree depends on the day you install rather than on the version of react-scan you asked for. [email protected] installed in May and [email protected] installed today are different dependency graphs.
Why this matters
Reproducibility. A lockfile protects a project that already has one, but it does not help a fresh npm i react-scan, a lockfile regeneration, a bot-driven re-resolution, or anyone reproducing a bug report. #467 illustrates this: the reporter's environment lists react-grab: 0.1.37, while latest today is 0.1.50. Two people following identical steps get different trees, which makes triage harder than it needs to be.
Release cadence makes the window wide. react-grab has 146 stable releases (269 including prereleases), 18 of them in the last 90 days, with the most recent on 2026-07-23. has 624 published versions, most recent 2026-07-25. These are not dormant packages where a floating tag would be harmless.