Skip to content

fix(release): keep package-lock.json in sync with the version bump - #88

Merged
luoxuanzao merged 1 commit into
mainfrom
fix/release-lock-sync
Sep 29, 2026
Merged

luoxuanzao merged 1 commit into
mainfrom
fix/release-lock-sync

Conversation

@luoxuanzao

Copy link
Copy Markdown
Member

Summary

  • Release commits bumped package.json but never package-lock.json, so the lock kept the previous version and every npm install showed it as dirty in every worktree.
  • scripts/sync-version.js now rewrites the lock's root version and packages[""].version; the version npm script stages the lock; release:check fails when lock and package versions disagree.

Verification

  • Forced a 1.0.15/1.0.16 mismatch: npm run release:check fails with the new message, node scripts/sync-version.js fixes it, check passes again
  • Rewritten lock is byte-identical to npm's own output (no formatting churn)
  • npm run lint, npm run test (171 suites, 3600 tests)

Release commits bumped package.json, manifest.json and versions.json but
left package-lock.json carrying the previous version, so every npm install
rewrote the lock's root version and showed the file as dirty in every
worktree. sync-version now rewrites the lock's root entries too, the version
script stages it, and release:check fails when the two disagree.

Co-authored-by: QoderAI (Qwen 3.8 Max) <qoder_ai@qoder.com>
@luoxuanzao
luoxuanzao merged commit d813f3b into main Sep 29, 2026
10 checks passed
@luoxuanzao
luoxuanzao deleted the fix/release-lock-sync branch September 29, 2026 23:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant