Skip to content

ci: pin npm 11 so dep bumps stop desyncing the lockfile - #48

Merged
Rinse12 merged 1 commit into
masterfrom
ci/pin-npm-11
Sep 3, 2026
Merged

Rinse12 merged 1 commit into
masterfrom
ci/pin-npm-11

Conversation

@Rinse12

@Rinse12 Rinse12 commented Sep 3, 2026

Copy link
Copy Markdown
Member

Every dependency bump in this repo has to have its lockfile regenerated with npx npm@10 or CI fails. 5b1728b did exactly that for the 0.0.92 bump; #46 hit it again for 0.0.94. This retires the workaround.

The problem

Node 22 bundles npm 10.9.x, but the repo is developed on npm 11, and the two disagree on lockfile shape. npm 11 prunes entries (utf-8-validate@5.0.10 and friends) that npm 10 then reports as Missing from lock file and refuses to install:

npm error code EUSAGE
npm error `npm ci` can only install packages when your package.json and
npm error package-lock.json or npm-shrinkwrap.json are in sync.
npm error Missing: utf-8-validate@5.0.10 from lock file

So a lockfile regenerated on any dev machine breaks CI, and the only workaround is remembering to shell out to an npm you don't otherwise use.

The fix

  • npm i -g npm@11.13.0 in both jobs, immediately after setup-node and before npm ci
  • packageManager: "npm@11.13.0" + engines.npm: ">=11" so the requirement is declared, not just enforced in CI
  • package-lock.json regenerated with npm 11, so the committed lockfile is the shape CI actually installs

Same fix this library's consumers already carry — pubsub-voting-testing-on-real-website dfc1b7f (packageManager + engines + Netlify NPM_VERSION) and pkc-js 516431d98 (the release job).

Why release.yml too, not just ci.yml

release-it's before:git:release hook runs npm i --package-lock-only (see config/.release-it.json), so the release bot rewrites the lockfile with whatever npm it has. Pinning only CI would mean every release silently re-broke master — which is precisely the failure pkc-js 516431d98 was written to stop.

Verification

On npm 11.13.0, everything CI runs passes: npm ci, typecheck, typecheck:examples, typecheck:tests, build, 509 unit tests, 12 integration tests.

And the pin is load-bearing rather than decorative — npx npm@10 ci --dry-run against this branch now fails with the EUSAGE/Missing: utf-8-validate error. Without the workflow change, this lockfile would break CI; with it, both agree.

Node 22 bundles npm 10.9.x, but this repo is developed on npm 11, and the two
disagree on lockfile shape: npm 11 prunes entries (utf-8-validate@5.0.10 and
friends) that npm 10 then reports as `Missing from lock file` and refuses to
`npm ci`. Every dependency bump therefore had to have its lockfile regenerated
with `npx npm@10` or CI failed — 5b1728b did exactly that for the 0.0.92 bump,
and #46 hit it again for 0.0.94.

Pin npm 11.13.0 in both jobs, declare it via packageManager + engines, and
regenerate package-lock.json with npm 11 so the committed lockfile is the shape
CI actually installs. Same fix this library's consumers already carry:
pubsub-voting-testing-on-real-website dfc1b7f (packageManager + engines +
Netlify NPM_VERSION) and pkc-js 516431d98 (the release job).

release.yml is pinned too, not just ci.yml: release-it's before:git:release hook
runs `npm i --package-lock-only`, so the release bot rewrites the lockfile with
whatever npm it has. Pinning only CI would mean every release re-broke master.

Verified locally on npm 11.13.0: npm ci, typecheck, typecheck:examples,
typecheck:tests, build, 509 unit tests, 12 integration tests — all pass. And
`npx npm@10 ci --dry-run` now fails with the EUSAGE/Missing error, confirming
the pin is load-bearing rather than decorative.
@coderabbitai

coderabbitai Bot commented Sep 3, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 16 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Team

Run ID: c0d5b293-51f7-41e4-af1a-c1b6c41d76d8

📥 Commits

Reviewing files that changed from the base of the PR and between 644a7af and d0d9bbd.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (3)
  • .github/workflows/ci.yml
  • .github/workflows/release.yml
  • package.json

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Rinse12
Rinse12 merged commit ad611fc into master Sep 3, 2026
3 checks passed
@tomcasaburi
tomcasaburi deleted the ci/pin-npm-11 branch September 22, 2026 11:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant