package.json and Versions

package.json, Semantic Versioning and package-lock.json

Cordova 129 keeps two lists in package.json: platforms and plugins as devDependencies with version ranges, and their names under a cordova key, which cordova prepare restores from. Replace the template's description and author with npm 2,036 pkg:

Setting package.json fields and listing the installed platformsJSON
npm pkg set description="A small bookshop: six books, their details and a cart." \
  author="BookNest Team"
npm ls --depth=0
Output
com.example.booknest@1.0.0 /home/dev/lane-ch1/booknest
├── cordova-android@15.1.0
└── cordova-browser@7.0.0

Versions follow semantic versioning, MAJOR.MINOR.PATCH: patches fix bugs, minor releases add features compatibly, majors may break you. The range prefix says which updates npm may install:

npm version ranges
Range Accepts Example for 15.1.0
^15.1.0 (caret, npm's default) Minor and patch updates 15.1.0 up to, not including, 16.0.0
~15.1.0 (tilde) Patch updates only 15.1.0 up to, not including, 15.2.0
15.1.0 That version only 15.1.0

package-lock.json records the exact version and integrity hash of every package in the tree, so a clone installs what you tested. Commit it, and use npm ci in build scripts: it installs exactly the lock file. Upgrade a platform deliberately, with cordova platform rm android and cordova platform add android@latest.