Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Use `npm ci` instead of `npm install` in CI and deploy workflows

オープン 初心者向け
#294 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
2/5
見積もり時間
1〜3時間
初心者へのやさしさ
84/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
github-actions, javascript, node.js
領域
ci-cd

調査の方向性

.github/workflows/cd_dev.yaml と .github/workflows/cd_prod.yaml にある影響を受ける4つのインストール手順から始め、その後、周辺のテストおよびデプロイジョブを確認します。ワークフローを実行するか、クリーンなディレクトリで npm ci を検証し、両方のワークフローが package-lock.json を変更せずに完了すること、また本番環境の前に dev デプロイが正常であることを確認します。

索引モデルが issue の本文から書いたものです。

説明

backend dependencies easy

Summary

Every workflow that installs dependencies runs npm install. It should run npm ci, so that CI and the deploy servers install exactly the tree recorded in package-lock.json.

Why this matters

npm install is allowed to resolve newer versions inside the declared semver ranges and to rewrite package-lock.json in place. Two consequences:

  • The CI test job can pass against a dependency tree that is not the one reviewed and approved in the PR.
  • The deploy servers can install a tree that was never tested anywhere.

npm ci installs the lockfile exactly, never writes to it, and fails loudly if package.json and package-lock.json have drifted apart.

This surfaced while reviewing #293, which curates the dependency set so that npm-check and npm audit are both clean. That work only holds if the lockfile is what actually gets installed.

Affected lines

File Line Current
.github/workflows/cd_dev.yaml 29 run: npm install (test job)
.github/workflows/cd_dev.yaml 59 npm install (deploy step)
.github/workflows/cd_prod.yaml 31 run: npm install (test job)
.github/workflows/cd_prod.yaml 58 npm install (deploy step)

Proposed change

Test jobs:

      - name: Install dependencies
        run: npm ci
      - name: Generate coverage report
        run: npm run coverage:ci

Deploy steps: npm ci. Worth considering npm ci --omit=dev on the deploy steps as well, since a bare install currently puts c8, supertest, yargs, glob, and the rest of the test tooling into production node_modules. That is a related but separable concern — happy to split it into its own issue if preferred.

Notes

  • The lockfile is already ci-ready. Verified on the 8-24-26-packages branch: npm ci in a clean directory installs 169 packages and reports 0 vulnerabilities.
  • npm ci requires package-lock.json to exist and to agree with package.json. Both hold today.
  • npm ci deletes node_modules before installing. On the self-hosted deploy runners (vlcdhp02, vlcdhprdp02) this makes installs slower but reproducible. The actions/cache@v4 step already in both workflows should absorb most of that cost on the GitHub-hosted test jobs.

Acceptance criteria

  • cd_dev.yaml and cd_prod.yaml use npm ci in the test jobs
  • cd_dev.yaml and cd_prod.yaml use npm ci in the deploy steps
  • A CI run completes with package-lock.json unmodified afterward
  • Dev deploy verified healthy before the same change reaches prod
主要言語
JavaScript
スター
3
フォーク
6
平均マージ
4日 9時間
マージ済み PR(30日)
5

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

CenterForDigitalHumanities/rerum_server_nodejs のほかの issue

CenterForDigitalHumanities/rerum_server_nodejs の issue をすべて見る

似ている issue

JavaScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。