Use `npm ci` instead of `npm install` in CI and deploy workflows
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 2/5
- Tempo stimato
- 1-3 ore
- Idoneità per principianti
- 84/100
- Tipo di issue
- Bug
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Attiva
- Stack tecnologico
- github-actions, javascript, node.js
- Ambito
- ci-cd
Direzione di ricerca
Inizia con i quattro passaggi di installazione interessati in .github/workflows/cd_dev.yaml e .github/workflows/cd_prod.yaml, quindi esamina i job di test e deploy circostanti. Esegui i workflow o valida npm ci in una directory pulita e conferma che entrambi i workflow vengano completati con package-lock.json invariato e che il deploy dev sia in buone condizioni prima della produzione.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Summary
Every workflow that installs dependencies runs npm install. It should run npm ci, so that CI and the deploy servers install exactly the tree recorded in package-lock.json.
Why this matters
npm install is allowed to resolve newer versions inside the declared semver ranges and to rewrite package-lock.json in place. Two consequences:
- The CI test job can pass against a dependency tree that is not the one reviewed and approved in the PR.
- The deploy servers can install a tree that was never tested anywhere.
npm ci installs the lockfile exactly, never writes to it, and fails loudly if package.json and package-lock.json have drifted apart.
This surfaced while reviewing #293, which curates the dependency set so that npm-check and npm audit are both clean. That work only holds if the lockfile is what actually gets installed.
Affected lines
| File | Line | Current |
|---|---|---|
.github/workflows/cd_dev.yaml |
29 | run: npm install (test job) |
.github/workflows/cd_dev.yaml |
59 | npm install (deploy step) |
.github/workflows/cd_prod.yaml |
31 | run: npm install (test job) |
.github/workflows/cd_prod.yaml |
58 | npm install (deploy step) |
Proposed change
Test jobs:
- name: Install dependencies
run: npm ci
- name: Generate coverage report
run: npm run coverage:ci
Deploy steps: npm ci. Worth considering npm ci --omit=dev on the deploy steps as well, since a bare install currently puts c8, supertest, yargs, glob, and the rest of the test tooling into production node_modules. That is a related but separable concern — happy to split it into its own issue if preferred.
Notes
- The lockfile is already
ci-ready. Verified on the8-24-26-packagesbranch:npm ciin a clean directory installs 169 packages and reports 0 vulnerabilities. npm cirequirespackage-lock.jsonto exist and to agree withpackage.json. Both hold today.npm cideletesnode_modulesbefore installing. On the self-hosted deploy runners (vlcdhp02,vlcdhprdp02) this makes installs slower but reproducible. Theactions/cache@v4step already in both workflows should absorb most of that cost on the GitHub-hosted test jobs.
Acceptance criteria
-
cd_dev.yamlandcd_prod.yamlusenpm ciin the test jobs -
cd_dev.yamlandcd_prod.yamlusenpm ciin the deploy steps - A CI run completes with
package-lock.jsonunmodified afterward - Dev deploy verified healthy before the same change reaches prod
- Lingua principale
- JavaScript
- Stelle
- 3
- Fork
- 6
- Merge medio
- 4g 9h
- PR unite (30g)
- 5
Preparare l'ambiente
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di CenterForDigitalHumanities/rerum_server_nodejs
-
bug documentation
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
CenterForDigitalHumanities/rerum_server_nodejs#290 · 1 commento ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 50/100
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 74/100
-
Code Cleanup EpicAperta
Difficoltà 4/5 3-5 giorni Idoneità per principianti 35/100
Tutte le issue di CenterForDigitalHumanities/rerum_server_nodejs
Issue simili
-
bug CI breakage triage needed
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
oppia/oppia#27517 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
draftomen enhancement size: S
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
andreagrandi/draftomen#761 ·
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 92/100
HarperFast/harper#2866 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
HarperFast/harper-pro#927 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
anthropics/skills#1897 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno