Does anybody know of a blogpost about using a composer.lock file in a library? In combination with upgrading to newer dependencies with dependabot.
know some people do it.
Looking for pro's/con's and things I need to look out for.