Skip to content

fix: refresh the lockfile after upgrade's version reconcile - #24

Merged
kboshold merged 2 commits into
mainfrom
fix/upgrade-stale-lockfile
Sep 25, 2026
Merged

kboshold merged 2 commits into
mainfrom
fix/upgrade-stale-lockfile

Conversation

@kboshold

@kboshold kboshold commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator

What

upgrade now installs once more after its sync when the version reconcile changed package.json and a lockfile exists. The second install runs without a prompt, since the user already agreed to the first one. If it fails, the upgrade rolls back like it does for any other failure after the install.

The e2e upgrade leg now reconciles only engines.node and checks that the lockfile matches package.json. The fixture's made-up devDependency and postinstall cannot be installed, and the leg now runs a real second install.

Why

upgrade ran the install before the sync raised the version ranges from the new profile. The lockfile then no longer matched package.json, and pnpm install --frozen-lockfile failed with ERR_PNPM_OUTDATED_LOCKFILE. The only sign of this was the stale-lockfile hint, and nothing acts on it in --json runs such as automated upgrades.

upgrade installed before its chained sync raised the version ranges in package.json, so the lockfile no longer matched and a frozen install failed. When the sync reports a stale lockfile, install once more without prompting. A failure rolls back like any other post-install error.
upgrade now installs after the reconcile, so the fixture's fake devDependency and postinstall would fail it. The leg reconciles engines.node instead and checks that the lockfile matches.
@kboshold
kboshold merged commit 62640a5 into main Sep 25, 2026
8 checks passed
@kboshold
kboshold deleted the fix/upgrade-stale-lockfile branch September 25, 2026 13:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant