Skip to content

Keep the lockfile version in step with releases - #144

Merged
noisyneuron merged 1 commit into
mainfrom
sukanya/sync-package-lock
Sep 17, 2026
Merged

noisyneuron merged 1 commit into
mainfrom
sukanya/sync-package-lock

Conversation

@noisyneuron

Copy link
Copy Markdown
Contributor

Releasing bumps the package version without touching the lockfile's copy of it, so the two have drifted since 1.10.2 and only get reconciled when someone happens to run an install and commit the noise in an unrelated PR. The release script now syncs the lockfile immediately after versioning and commits it alongside the docs and changeset metadata, and npm run check fails whenever the two versions disagree, so the drift can't reappear silently by any route. The lockfile is also brought up to the current 1.11.0.

Test plan

  1. Run npm run check:lockfile. You should see it report that the lockfile matches 1.11.0.
  2. Edit the top-level version in package-lock.json to any other value and run npm run check:lockfile again. Observe that it fails, names both versions, and tells you to run npm install --package-lock-only.

Made with Cursor

Co-authored-by: Cursor <cursoragent@cursor.com>
@noisyneuron
noisyneuron marked this pull request as ready for review September 17, 2026 11:51

@chadlawlis chadlawlis left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for this – makes sense and works as expected.

@noisyneuron
noisyneuron merged commit 7e93935 into main Sep 17, 2026
3 checks passed
@noisyneuron
noisyneuron deleted the sukanya/sync-package-lock branch September 17, 2026 14:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants