- third-party dependencies must have their version pinned - not the case for cozy dependencies As dependencies contain native code it is very important to do it in a delicate manner, or we risk breaking the build