# Managing cookbok dependency versions on environments vs metadata

**URL:** <https://discourse.chef.io/t/managing-cookbok-dependency-versions-on-environments-vs-metadata/13841>\
**Category:** Chef Infra (archive)\
**Created:** [October 16, 2018, 5:22pm UTC](https://discourse.chef.io/t/managing-cookbok-dependency-versions-on-environments-vs-metadata/13841 "2018-10-16T17:22:58Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![lucasslima](https://avatars.discourse-cdn.com/v4/letter/l/848f3c/32.png) [@lucasslima](https://discourse.chef.io/u/lucasslima)\
**Post date:** [October 16, 2018, 5:22pm UTC](https://discourse.chef.io/t/managing-cookbok-dependency-versions-on-environments-vs-metadata/13841/1 "2018-10-16T17:22:58Z")

</div>

Hi,

I'm working with a company that sets the locks the cookbooks versions on environments. But, no cookbook has a dependency locked on the metadata, so when we updated a dependency like `ark 1.2.0` to `ark 1.3.0`, all the environment is impacted. I was arguing we should move to setting the dependencies versions on the cookbooks metadata, and only fix the versions of the cookbooks the company develops.

I wanted to ask about opinions on this, I already saw the discussion on

> [@Opinions on Cookbook version contraints - environment or cookbook](https://discourse.chef.io/t/opinions-on-cookbook-version-contraints-environment-or-cookbook/8189):
>
> We are re-evaluating this - should we add version contraints in our metadata or just do it in the environment. Thoughts? Opinions? What does the community do in regards to this? Thank you! Jenn

But I wanted to know what options people are using in 2018.

Thanks in advance!
