Skip to content

Fix CI: restore lockfile entries pruned by a Windows npm install - #22

Merged
aliihsaad merged 1 commit into
masterfrom
fix/ci-lockfile-sync
Sep 12, 2026
Merged

aliihsaad merged 1 commit into
masterfrom
fix/ci-lockfile-sync

Conversation

@aliihsaad

Copy link
Copy Markdown
Owner

Fixes the verify job failing on master since 049bf74.

Cause

npm error code EUSAGE
`npm ci` can only install packages when your package.json and package-lock.json are in sync
Missing: @emnapi/core@1.11.1 / @emnapi/runtime@1.11.1 / @emnapi/core@1.10.0 / @emnapi/runtime@1.10.0

The Next.js and sharp upgrade in acc1ba7 was made with npm install on Windows, where npm resolves optional dependencies for the host platform only. That pruned four dev/optional @emnapi entries under the wasm32-wasi resolver bindings, which a Linux npm ci still requires.

My local verification missed it: tsc, vitest and next build all reuse the existing node_modules, so none of them exercises the clean-room sync check that npm ci performs.

Fix

Diffing against the pre-upgrade lockfile showed the upgrade added 0 keys and removed exactly these 4 — all dev: true, optional: true, none related to next or sharp. That confirms platform pruning rather than a consequence of the version bump, so they are restored verbatim from acc1ba7^.

Restored preserving npm's original key ordering, so the change is 46 insertions, 0 deletions rather than a reshuffle of the whole file.

Locked versions are unchanged and correct: next 16.3.5, sharp 0.35.4, eslint-config-next 16.3.5.

Verification

npm ci --dry-run now passes the sync check that produced EUSAGE. 570/570 tests pass.

Note for future dependency bumps in this repo: run npm install on Linux (or verify with npm ci afterwards) before committing a lockfile, since a Windows install silently prunes cross-platform optional deps.

🤖 Generated with Claude Code

CI "verify" failed on master with:

  npm error code EUSAGE
  `npm ci` can only install packages when your package.json and
  package-lock.json are in sync
  Missing: @emnapi/core@1.11.1 from lock file
  Missing: @emnapi/runtime@1.11.1 from lock file
  Missing: @emnapi/core@1.10.0 from lock file
  Missing: @emnapi/runtime@1.10.0 from lock file

The Next.js/sharp upgrade in acc1ba7 was made with `npm install` on Windows,
where npm resolves optional dependencies for the host platform only. That
pruned four dev/optional @emnapi entries under the wasm32-wasi resolver
bindings, which a Linux `npm ci` still requires. Local verification missed it
because tsc, vitest and next build all reuse the existing node_modules; only a
clean-room `npm ci` exercises the sync check.

Diffing against the pre-upgrade lockfile showed the upgrade added 0 keys and
removed exactly these 4, all dev:true optional:true and unrelated to next or
sharp, confirming platform pruning rather than a consequence of the bump. They
are restored verbatim from acc1ba7^, preserving npm's original key ordering so
the change is 46 insertions and 0 deletions.

Locked versions are unchanged and correct: next 16.3.5, sharp 0.35.4,
eslint-config-next 16.3.5.

`npm ci --dry-run` now passes the sync check. 570/570 tests pass.
@vercel

vercel Bot commented Sep 12, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
social-media-manager-ai Ready Ready Preview Sep 12, 2026 3:06pm UTC

@coderabbitai

coderabbitai Bot commented Sep 12, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 12f5980c-c91a-4939-a319-4df3faebd70a


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@aliihsaad
aliihsaad merged commit 1301f34 into master Sep 12, 2026
4 checks passed

This branch was successfully deployed

1 active deployment
Preview — 26999e8c Deployed Sep 12, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant