In reply to @whentze:matrix.orgfor external stuff that's consuming nixpkgs, having the package.json and package-lock.json committed is actually totally fine