Dependency management | vasak-desktop

Complete guide to managing the project’s dependencies.

Frontend Dependencies (JavaScript/TypeScript)#

File: package.json#

The dependencies are defined in this file:

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
{
  "dependencies": {
    "vue": "^3.5.26",
    "vue-router": "^4.6.4",
    "pinia": "^3.0.4",
    "@tauri-apps/api": "^2.9.1",
    "@vasakgroup/plugin-bluetooth-manager": "^2.0.0"
  },
  "devDependencies": {
    "typescript": "^5.9.3",
    "vite": "^7.3.0",
    "tailwindcss": "^4.1.18"
  }
}

Install All Dependencies#

1
bun install

Adding a New Dependency#

1
2
3
4
bun add package-name

# dev dependency
bun add -D package-name

Updating Dependencies#

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
# See which packages have updates
bun outdated

# Update everything
bun update

# Update a specific package
bun add package-name@latest

# Update the major version (breaking changes)
bun add package-name@^5.0.0  # If it is on v4

Removing a Dependency#

1
2
# Bun
bun remove package-name

Cleaning Up Unused Dependencies#

1
2
# Bun
bun install --frozen-lockfile  # After removing them from package.json

Backend Dependencies (Rust)#

File: src-tauri/Cargo.toml#

Example structure:

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
[package]
name = "vasak-desktop"
version = "0.5.2"

[dependencies]
tauri = { version = "2", features = ["protocol-asset"] }
serde = { version = "1", features = ["derive"] }
tokio = { version = "1.0", features = ["full"] }
zbus = { version = "4", features = ["tokio"] }

[dev-dependencies]
tokio-test = "0.4"

Version Syntax#

  • 1.0 - Exact: version 1.0.0
  • ^1.0 - Compatible: 1.0 through 1.999
  • ~1.0 - Patch: only 1.0.x
  • 1.0.* - Patch: only 1.0.x
  • >=1.0, <2.0 - Range: from 1.0 up to but not including 2.0

Adding a Rust Dependency#

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
cd src-tauri

# Add a dependency
cargo add crate-name

# Add it with specific features
cargo add crate-name --features "feature1,feature2"

# Add a specific version
cargo add [email protected]

# Add it as a dev-dependency
cargo add --dev crate-name

Updating Rust Dependencies#

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
cd src-tauri

# See what has updates
cargo outdated

# Update everything
cargo update

# Update a specific crate
cargo update -p crate-name

# See the version changes
cargo update --verbose

Removing a Rust Dependency#

1
2
3
4
5
6
7
8
cd src-tauri

# Remove it
cargo remove crate-name

# Or edit Cargo.toml directly
# and run:
cargo update

Locking Versions (Lock Files)#

bun.lock (Frontend)#

  • Generated automatically by Bun
  • Holds the exact installed versions
  • Must be committed to Git
1
2
# Reinstall the exact versions from the lock file
bun install --frozen-lockfile

Cargo.lock (Backend)#

  • Generated automatically by Cargo
  • Must be committed to Git
1
2
# For libraries, it is usually not committed
# For executable applications, it is

Dependency Analysis#

Dependency Tree (Frontend)#

1
2
3
4
5
# See the dependency tree
bun ls --depth=10

# Filter by package
bun ls | grep pinia

Dependency Tree (Backend)#

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
cd src-tauri

# See the dependency tree
cargo tree

# Filter by dependency
cargo tree | grep serde

# See only direct dependencies
cargo tree --depth=1

Finding Duplicated Dependencies#

1
2
3
4
5
# Frontend
bun ls | grep -E "\s.*@"

# Backend
cargo tree | grep -E "├── |└── " | sort | uniq -d

Security Audit#

Frontend#

1
2
3
4
5
# With Bun
bun audit

# Fix with Bun
bun audit --fix

Backend#

1
2
3
4
5
6
7
cd src-tauri

# Audit the Rust dependencies
cargo audit

# Update crates with vulnerabilities
cargo update -p vulnerable-crate

Cache and Cleanup#

Clearing the npm/Bun Cache#

1
2
# Bun
bun pm cache rm --all

Clearing Cargo’s Cache#

1
2
3
4
5
# Cargo
cargo clean

# Registry cache
rm -rf ~/.cargo/registry/cache

Freeing Up Space#

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
# See how much space the dependencies take
du -sh node_modules/
du -sh src-tauri/target/

# Clean both
rm -rf node_modules/
rm -rf src-tauri/target/

# Reinstall
bun install
cargo build

Best Practices#

✅ Do:#

  • Commit the lock files (bun.lock, Cargo.lock)
  • Use exact versions for production
  • Audit dependencies regularly
  • Update dependencies incrementally
  • Document dependency changes

❌ Don’t:#

  • Delete lock files without a reason
  • Install * versions directly in production
  • Ignore security audits
  • Update all dependencies at once
  • Use very old versions

Useful Scripts#

Safe Update#

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
#!/bin/bash
# safe-update.sh

set -e

echo "🔄 Updating dependencies..."

# Frontend
echo "Frontend..."
bun outdated
bun update
bun install

# Backend
echo "Backend..."
cd src-tauri
cargo outdated
cargo update

# Verify the build
echo "Building..."
cd ..
bun run build --dry-run
cargo check

echo "✓ Update complete"