It's too easy to update a package.json (eg editing on github) without the accompanying lockfile getting updated.