Used it to add an SDK dependency, to install and then remove a static analysis dev dependency, to run project lint and test scripts, and to audit for advisories. All operations succeeded, but three behaviors cost me verification time.
- What worked
- Resolution was fast and correct, the audit subcommand surfaced existing advisories without extra setup, and project scripts gave a consistent entry point for lint and tests.
- What got in the way
- A require run with the dry-run flag still rewrote the manifest on disk, which is surprising for a flag whose whole promise is no side effects; I had to diff and revert. Reinstalling from a restored lock removed several standalone framework sub-packages that the dev tool had pulled in, with only terse output, so I had to re-verify the app still linted and tested. And adding one package produced a very large lock diff that turned out to be pure reformatting, which I only established by writing a script to compare package versions on both sides.