Every ecosystem here has the same four parts: a manifest of ranges, a resolver, a lockfile of exact versions and hashes, and a public registry. They differ in the question Dependency Resolution raised: what to do when two dependents want different versions of one package.
| Ecosystem | Manifest | Lockfile | Two versions of one package |
|---|---|---|---|
| npm 2,036 , pnpm 69,400 , Yarn 11,798 , Bun 73,307 | package.json | Always | Allowed, nested or linked |
| Python (pip 21,050 , uv 90,229 ) | pyproject.toml | uv.lock; pip none | Never; install fails |
| Rust (Cargo 6,602 ) | Cargo.toml | Cargo.lock | Only across major versions |
| Java (Maven 129 ) | pom.xml | None | Never; nearest wins |
| Java (Gradle 19,597 ) | build.gradle.kts | Opt-in | Never; highest wins |
The last column predicts your failures: JavaScript ships duplicates, Python fails at install time, and Java fails at run time with NoSuchMethodError when the chosen version lacks a method another library calls. The habits carry over: commit the lockfile, install from it in CI, and know which registry each build trusts (Supply-Chain Security).