All of our npm dependencies are locked via the yarn.lock file for the following reasons:

Before changing a dependency, do the following:

To add a new dependency do the following: yarn add <packagename> --dev

To update an existing dependency do the following: run yarn upgrade <packagename>@<version|latest> --dev or yarn upgrade <packagename> --dev to update to the latest version that matches version constraint in package.json

To Remove an existing dependency do the following: run yarn remove <packagename>

Once you've changed the dependency, commit the changes to package.json & yarn.lock, and you are done.