Skip to content

ci: make npm installs reproducible - #27

Merged
rogerchappel merged 2 commits into
mainfrom
agent/oss-9af121562ccb-lockfile-ci
Aug 23, 2026
Merged

rogerchappel merged 2 commits into
mainfrom
agent/oss-9af121562ccb-lockfile-ci

Conversation

@rogerchappel

Copy link
Copy Markdown
Owner

Summary

  • commit the npm v3 lockfile generated from package.json
  • make the Node CI path always install with npm ci
  • retain the existing release:check and package-smoke verification flow

Commits

  • build: commit npm lockfile — records the dependency graph required by clean installs
  • ci: require reproducible npm installs — removes unlocked installer and alternate-package-manager fallbacks

Verification

From a fresh detached worktree at the proposed head:

  • npm ci
  • git status --short (empty after install)
  • npm run release:check (21 tests, smoke, package smoke)
  • git status --short (empty after verification)
  • ruby -e 'require "yaml"; YAML.load_file(".github/workflows/ci.yml")'\n- git diff --check\n\nAll commands exited 0.

@rogerchappel

Copy link
Copy Markdown
Owner Author

Automated merge note

Triage class: auto-merge

Summary: Commits the npm lockfile and makes CI use reproducible npm ci installs while retaining release and package-smoke verification (2 files, +27/-33).

Checks run: GitHub CI Repository hygiene SUCCESS; fresh detached-worktree npm ci, clean status, npm run release:check (21/21 tests, smoke, package smoke), clean status, workflow YAML parse, and git diff --check passed.

Rebased/CI-repaired: No.

Verified head SHA: c7d2eeac72426397f05df757fafa619a9c865129.

@rogerchappel
rogerchappel merged commit 43b61b2 into main Aug 23, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant