fix: refresh the lockfile after upgrade's version reconcile - #24
Merged
Merged
Conversation
upgrade installed before its chained sync raised the version ranges in package.json, so the lockfile no longer matched and a frozen install failed. When the sync reports a stale lockfile, install once more without prompting. A failure rolls back like any other post-install error.
upgrade now installs after the reconcile, so the fixture's fake devDependency and postinstall would fail it. The leg reconciles engines.node instead and checks that the lockfile matches.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
upgradenow installs once more after its sync when the version reconcile changedpackage.jsonand a lockfile exists. The second install runs without a prompt, since the user already agreed to the first one. If it fails, the upgrade rolls back like it does for any other failure after the install.The e2e upgrade leg now reconciles only
engines.nodeand checks that the lockfile matchespackage.json. The fixture's made-up devDependency andpostinstallcannot be installed, and the leg now runs a real second install.Why
upgraderan the install before the sync raised the version ranges from the new profile. The lockfile then no longer matchedpackage.json, andpnpm install --frozen-lockfilefailed withERR_PNPM_OUTDATED_LOCKFILE. The only sign of this was the stale-lockfile hint, and nothing acts on it in--jsonruns such as automated upgrades.