What These Ecosystems Share

Every ecosystem here has the same four parts: a manifest of ranges, a resolver, a lockfile of exact versions and hashes, and a public registry. They differ in the question Dependency Resolution raised: what to do when two dependents want different versions of one package.

How five ecosystems handle a version conflict
Ecosystem Manifest Lockfile Two versions of one package
npm 2,036 , pnpm 69,400 , Yarn 11,798 , Bun 73,307 package.json Always Allowed, nested or linked
Python (pip 21,050 , uv 90,229 ) pyproject.toml uv.lock; pip none Never; install fails
Rust (Cargo 6,602 ) Cargo.toml Cargo.lock Only across major versions
Java (Maven 129 ) pom.xml None Never; nearest wins
Java (Gradle 19,597 ) build.gradle.kts Opt-in Never; highest wins

The last column predicts your failures: JavaScript ships duplicates, Python fails at install time, and Java fails at run time with NoSuchMethodError when the chosen version lacks a method another library calls. The habits carry over: commit the lockfile, install from it in CI, and know which registry each build trusts (Supply-Chain Security).