npm install does far more than download packages.It first reads your
package.json.Then it looks at your package-lock.json, which records the exact dependency versions your project expects.
Next it builds a dependency tree.
If Package A needs React 18.2.0 and Package B also needs React 18.2.0, npm can reuse that version.
If another package requires React 17, npm may install both versions because their requirements don't match.
Only after resolving that entire tree does npm download packages and place them into
node_modules.That's why deleting
package-lock.json can unexpectedly change working code.The lock file isn't just a cache. It's a snapshot of the dependency tree your project was built and tested with.
