Skip to content

Sjip 1613/make npm installs reproducible - #1032

Merged
evans-g-crsj merged 4 commits into
devfrom
SJIP-1613/make-npm-installs-reproducible
Sep 22, 2026
Merged

evans-g-crsj merged 4 commits into
devfrom
SJIP-1613/make-npm-installs-reproducible

Conversation

@evans-g-crsj

Copy link
Copy Markdown
Collaborator

Generating Content ....

Both quality workflows triggered only on pull_request to main while PRs target
dev, so neither has been running at all. They now run on dev as well.

tests.yml installs with npm ci instead of npm i, so lockfile drift fails a PR
rather than a Netlify deploy. Both workflows pin node through setup-node and
node-version-file.

actions/checkout aligned to v4 everywhere; v3 runs the deprecated node 16
runtime.
Adds .nvmrc (22.23.2), .npmrc with engine-strict=true, and an engines field
allowing node 22-23 and npm 10-11.

A lockfile is a function of the npm that writes it, so an unpinned toolchain
makes drift inevitable. This is the third recurrence; see SJIP-1580 and
SJIP-1520.

Follow-up: remove NODE_VERSION from the Netlify dashboard so .nvmrc is the
single source of truth.
npm ci failed on dev as of c60c830 with "Missing: yaml@2.9.1 from lock file".
Regenerated with npm install: +41 lines, no version changes, nothing removed.
npm ci verified passing afterwards.
@netlify

netlify Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for include-qa ready!

Name Link
🔨 Latest commit a558a52
🔍 Latest deploy log https://app.netlify.com/projects/include-qa/deploys/6ab189903277a60008a8222f
😎 Deploy Preview https://deploy-preview-1032--include-qa.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@github-actions

github-actions Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Project Coverage and Test

Coverage summary
Statements : Unknown% ( 0/0 )
Branches : Unknown% ( 0/0 )
Functions : Unknown% ( 0/0 )
Lines : Unknown% ( 0/0 )

Test Suites: 6 failed, 6 total
Tests: 0 total
Snapshots: 0 total
Time: 2.868 s
Ran all test suites.

@github-actions

github-actions Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Coverage report

St.❔
Category Percentage Covered / Total
🟢 Statements 100% 0/0
🟢 Branches 100% 0/0
🟢 Functions 100% 0/0
🟢 Lines 100% 0/0

Test suite run success

0 tests passing in 0 suite.

Report generated by 🧪jest coverage report action from a558a52

The extract_parts step used git log --pretty=%B which feeds the whole commit
message into the regex. Capture group 5 then swallowed the body and
$GITHUB_OUTPUT rejected the multi-line value with "Invalid format".

Switches to %s so only the subject line is parsed. Same fix already applied in
kf-portal-ui under SKFP-1619.
@evans-g-crsj
evans-g-crsj merged commit 0877e28 into dev Sep 22, 2026
9 checks passed
@evans-g-crsj
evans-g-crsj deleted the SJIP-1613/make-npm-installs-reproducible branch September 22, 2026 14:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants