Cordova 129 keeps two lists in package.json: platforms and plugins as devDependencies with version ranges, and their names under a cordova key, which cordova prepare restores from. Replace the template's description and author with npm 2,036 pkg:
npm pkg set description="A small bookshop: six books, their details and a cart." \
author="BookNest Team"
npm ls --depth=0com.example.booknest@1.0.0 /home/dev/lane-ch1/booknest ├── cordova-android@15.1.0 └── cordova-browser@7.0.0
Versions follow semantic versioning, MAJOR.MINOR.PATCH: patches fix bugs, minor releases add features compatibly, majors may break you. The range prefix says which updates npm may install:
| Range | Accepts | Example for 15.1.0 |
|---|---|---|
| ^15.1.0 (caret, npm's default) | Minor and patch updates | 15.1.0 up to, not including, 16.0.0 |
| ~15.1.0 (tilde) | Patch updates only | 15.1.0 up to, not including, 15.2.0 |
| 15.1.0 | That version only | 15.1.0 |
package-lock.json records the exact version and integrity hash of every package in the tree, so a clone installs what you tested. Commit it, and use npm ci in build scripts: it installs exactly the lock file. Upgrade a platform deliberately, with cordova platform rm android and cordova platform add android@latest.