Package-lock is useful to be able to "timetravel" to see what kind of librarysets were used with older working builds, but to make sure that this package works correctly for the end user the latest available packages should be used for testing.
sindresorhus/ama#479 (comment)