Use `npm ci` instead of `npm install` in CI and deploy workflows
まだ誰も着手していません。
評価
- 難易度
- 2/5
- 見積もり時間
- 1〜3時間
- 初心者へのやさしさ
- 84/100
- issue の種類
- バグ
- 明瞭さ
- 明確に書かれている
- 活発さ
- 活発
- 技術スタック
- github-actions, javascript, node.js
- 領域
- ci-cd
調査の方向性
.github/workflows/cd_dev.yaml と .github/workflows/cd_prod.yaml にある影響を受ける4つのインストール手順から始め、その後、周辺のテストおよびデプロイジョブを確認します。ワークフローを実行するか、クリーンなディレクトリで npm ci を検証し、両方のワークフローが package-lock.json を変更せずに完了すること、また本番環境の前に dev デプロイが正常であることを確認します。
索引モデルが issue の本文から書いたものです。
説明
Summary
Every workflow that installs dependencies runs npm install. It should run npm ci, so that CI and the deploy servers install exactly the tree recorded in package-lock.json.
Why this matters
npm install is allowed to resolve newer versions inside the declared semver ranges and to rewrite package-lock.json in place. Two consequences:
- The CI test job can pass against a dependency tree that is not the one reviewed and approved in the PR.
- The deploy servers can install a tree that was never tested anywhere.
npm ci installs the lockfile exactly, never writes to it, and fails loudly if package.json and package-lock.json have drifted apart.
This surfaced while reviewing #293, which curates the dependency set so that npm-check and npm audit are both clean. That work only holds if the lockfile is what actually gets installed.
Affected lines
| File | Line | Current |
|---|---|---|
.github/workflows/cd_dev.yaml |
29 | run: npm install (test job) |
.github/workflows/cd_dev.yaml |
59 | npm install (deploy step) |
.github/workflows/cd_prod.yaml |
31 | run: npm install (test job) |
.github/workflows/cd_prod.yaml |
58 | npm install (deploy step) |
Proposed change
Test jobs:
- name: Install dependencies
run: npm ci
- name: Generate coverage report
run: npm run coverage:ci
Deploy steps: npm ci. Worth considering npm ci --omit=dev on the deploy steps as well, since a bare install currently puts c8, supertest, yargs, glob, and the rest of the test tooling into production node_modules. That is a related but separable concern — happy to split it into its own issue if preferred.
Notes
- The lockfile is already
ci-ready. Verified on the8-24-26-packagesbranch:npm ciin a clean directory installs 169 packages and reports 0 vulnerabilities. npm cirequirespackage-lock.jsonto exist and to agree withpackage.json. Both hold today.npm cideletesnode_modulesbefore installing. On the self-hosted deploy runners (vlcdhp02,vlcdhprdp02) this makes installs slower but reproducible. Theactions/cache@v4step already in both workflows should absorb most of that cost on the GitHub-hosted test jobs.
Acceptance criteria
-
cd_dev.yamlandcd_prod.yamlusenpm ciin the test jobs -
cd_dev.yamlandcd_prod.yamlusenpm ciin the deploy steps - A CI run completes with
package-lock.jsonunmodified afterward - Dev deploy verified healthy before the same change reaches prod
- 主要言語
- JavaScript
- スター
- 3
- フォーク
- 6
- 平均マージ
- 4日 9時間
- マージ済み PR(30日)
- 5
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
CenterForDigitalHumanities/rerum_server_nodejs のほかの issue
-
bug documentation
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
CenterForDigitalHumanities/rerum_server_nodejs#290 · コメント 1 件 ·
-
難易度 4/5 3〜5日 初心者へのやさしさ 50/100
-
難易度 3/5 1〜2日 初心者へのやさしさ 74/100
-
Code Cleanup Epicオープン
難易度 4/5 3〜5日 初心者へのやさしさ 35/100
CenterForDigitalHumanities/rerum_server_nodejs の issue をすべて見る
似ている issue
-
Mend: dependency security vulnerability untriaged
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
opensearch-project/security-dashboards-plugin#2543 ·
メンテナーはふだん 1 日以内に返信
-
[quality] refresh-radar-reports.yml runs on ubuntu-latest while every other job pins ubuntu-24.04オープンagent/quality hive/hosted-available-lke648397-260827-5n31 quality testing
難易度 1/5 1〜3時間 初心者へのやさしさ 90/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 65/100
godotengine/godot-website#1432 ·
-
Add: Mooz Retroオープンchannels:add check:passed
難易度 2/5 1〜3時間 初心者へのやさしさ 65/100
メンテナーはふだん 2 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 90/100
メンテナーはふだん 1 日以内に返信