Fix CI: restore lockfile entries pruned by a Windows npm install - #22
Merged
Merged
Conversation
CI "verify" failed on master with: npm error code EUSAGE `npm ci` can only install packages when your package.json and package-lock.json are in sync Missing: @emnapi/core@1.11.1 from lock file Missing: @emnapi/runtime@1.11.1 from lock file Missing: @emnapi/core@1.10.0 from lock file Missing: @emnapi/runtime@1.10.0 from lock file The Next.js/sharp upgrade in acc1ba7 was made with `npm install` on Windows, where npm resolves optional dependencies for the host platform only. That pruned four dev/optional @emnapi entries under the wasm32-wasi resolver bindings, which a Linux `npm ci` still requires. Local verification missed it because tsc, vitest and next build all reuse the existing node_modules; only a clean-room `npm ci` exercises the sync check. Diffing against the pre-upgrade lockfile showed the upgrade added 0 keys and removed exactly these 4, all dev:true optional:true and unrelated to next or sharp, confirming platform pruning rather than a consequence of the bump. They are restored verbatim from acc1ba7^, preserving npm's original key ordering so the change is 46 insertions and 0 deletions. Locked versions are unchanged and correct: next 16.3.5, sharp 0.35.4, eslint-config-next 16.3.5. `npm ci --dry-run` now passes the sync check. 570/570 tests pass.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes the
verifyjob failing on master since 049bf74.Cause
The Next.js and sharp upgrade in
acc1ba7was made withnpm installon Windows, where npm resolves optional dependencies for the host platform only. That pruned fourdev/optional@emnapientries under the wasm32-wasi resolver bindings, which a Linuxnpm cistill requires.My local verification missed it:
tsc,vitestandnext buildall reuse the existingnode_modules, so none of them exercises the clean-room sync check thatnpm ciperforms.Fix
Diffing against the pre-upgrade lockfile showed the upgrade added 0 keys and removed exactly these 4 — all
dev: true, optional: true, none related to next or sharp. That confirms platform pruning rather than a consequence of the version bump, so they are restored verbatim fromacc1ba7^.Restored preserving npm's original key ordering, so the change is 46 insertions, 0 deletions rather than a reshuffle of the whole file.
Locked versions are unchanged and correct:
next 16.3.5,sharp 0.35.4,eslint-config-next 16.3.5.Verification
npm ci --dry-runnow passes the sync check that produced EUSAGE. 570/570 tests pass.Note for future dependency bumps in this repo: run
npm installon Linux (or verify withnpm ciafterwards) before committing a lockfile, since a Windows install silently prunes cross-platform optional deps.🤖 Generated with Claude Code