Skip to content

chore: fail the publish workflow on lockfile version drift - #3

Merged
hamr0 merged 1 commit into
mainfrom
chore/lockfile-check
Sep 20, 2026
Merged

hamr0 merged 1 commit into
mainfrom
chore/lockfile-check

Conversation

@hamr0

@hamr0 hamr0 commented Sep 20, 2026

Copy link
Copy Markdown
Owner

package-lock.json carries its own copy of the project version, and /release
bumps package.json without running an install — so the lockfile's version
silently falls behind, sometimes by several minors. npm ci does not catch this:
it only compares dependency entries, never the project's own version field.

Harmless to consumers (npm does not ship a library's lockfile in the tarball),
but it is drift, and it is invisible.

This adds a Lockfile version matches package.json step to publish.yml,
running npm run check:lockfile --if-present. The --if-present is
load-bearing: a repo without the script no-ops instead of failing.

CHANGELOG updated. No version bump, no publish.

🤖 Generated with Claude Code

`npm ci` already fails when package-lock.json's DEPENDENCY entries disagree
with package.json. It does not check the lockfile's copy of this project's own
version — the field a release bumps in package.json while running no install.
Nothing caught that: measured in bareguard, where the lockfile sat at 0.13.0
while 0.14.0, 0.15.0 and 0.16.0 all shipped.

Adds `scripts/check-lockfile.mjs` / `npm run check:lockfile`, comparing both
places npm writes the version (the lockfile root and `packages[""]`), wired
into the publish workflow via `--if-present` beside the existing Typecheck
step. A missing lockfile exits 0 — some repos deliberately ship without one
and this step is shared across all of them.

Harmless to consumers: npm does not include a library's lockfile in the
published tarball. This is repo hygiene, and a hard failure only because it is
trivially fixable and compares two numbers this repo owns.

Propagated from bareguard along with the canonical PUBLISH_TEMPLATE.yml.
Branch pushed only — not merged, no version bump, no publish.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@hamr0
hamr0 merged commit 4a4b922 into main Sep 20, 2026
1 check passed
@hamr0
hamr0 deleted the chore/lockfile-check branch September 20, 2026 08:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant