Skip to content

Stop tracking package-lock.json - #4

Merged
imanimanyara merged 1 commit into
mainfrom
chore/untrack-lock
Oct 1, 2026
Merged

imanimanyara merged 1 commit into
mainfrom
chore/untrack-lock

Conversation

@imanimanyara

Copy link
Copy Markdown
Member

tabar is a library: consumers never install from its lock file, and CI should resolve fresh to catch what consumers will get. CI and release now run npm install, with the npm cache keyed on package.json.

The visual job was pinned to a Playwright image matching the version in the lock. Without the lock, a new job resolves the version from package.json and the visual job runs in that version's image. @playwright/test narrows from ^1.61.0 to ~1.61.0, still a range, so a minor bump stays a deliberate change that refreshes the screenshot baselines.

Verified without the lock: install, lint, typecheck, 147 tests and build pass; Playwright resolves 1.61.1, whose image exists. The visual tests need that container and run first in this pull request's CI. The lock file stays on disk, now ignored.

tabar is a library: consumers never install from its lock file, and CI should resolve fresh to catch what consumers will get. CI and release now run npm install, with the npm cache keyed on package.json.

The visual job was pinned to a Playwright image matching the version in the lock. Without the lock, a new job resolves the version from package.json and the visual job runs in that version's image. @playwright/test narrows from ^1.61.0 to ~1.61.0, still a range, so a minor bump stays a deliberate change that refreshes the screenshot baselines.

Verified without the lock: install, lint, typecheck, 147 tests and build pass; Playwright resolves 1.61.1, whose image exists. The visual tests need that container and run first in this pull request's CI. The lock file stays on disk, now ignored.
Copilot AI balanced review requested due to automatic review settings October 1, 2026 22:48
@imanimanyara
imanimanyara merged commit 073e745 into main Oct 1, 2026
6 checks passed

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Contributor instructions now fail without a lock file, and the visual job can install a different Playwright version than its container.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Stops tracking the npm lock file so library CI resolves consumer-visible dependency ranges.

Changes:

  • Ignores and removes package-lock.json.
  • Uses npm install with package-based cache keys.
  • Dynamically aligns the visual-test container with Playwright’s resolved version.
File Description
.gitignore Ignores the npm lock file.
package-lock.json Removes the tracked dependency lock.
package.json Restricts Playwright updates to patch releases.
.github/​workflows/​ci.yml Adds dynamic Playwright resolution and lock-free installs.
.github/​workflows/​release.yml Uses lock-free installation during releases.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/ci.yml
cache: npm
- run: npm ci
cache-dependency-path: package.json
- run: npm install --no-audit --no-fund
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants