Skip to content

Commit 0411722

Browse files
authored
Merge pull request #19 from handrews/fix/sync-lockfile-packaged-lock
Fix/sync lockfile packaged lock
2 parents fc6c089 + 435db89 commit 0411722

8 files changed

Lines changed: 6016 additions & 9 deletions

‎CONTRIBUTING.md‎

Lines changed: 18 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -148,10 +148,24 @@ When setting up a new specification repository whose only npm dependency is
148148
`@oai/build-infra`, the consumer `package-lock.json` should contain the
149149
dependency tree needed by the resolved build-infra commit. If `npm ci` reports
150150
missing or invalid transitive packages after adding build-infra, compare the
151-
consumer lockfile with this repository's verified `package-lock.json` and make
152-
sure the consumer lockfile includes the same transitive package entries. This is
153-
especially important for optional dependencies, because those are where
154-
platform-specific lockfile gaps usually appear.
151+
consumer lockfile with this repository's verified `package-lock.json`, or run
152+
`oai-spec-sync-lockfile` in the consumer repository, and make sure the consumer
153+
lockfile includes the same transitive package entries. This is especially
154+
important for optional dependencies, because those are where platform-specific
155+
lockfile gaps usually appear.
156+
157+
The sync helper uses the packaged snapshot at
158+
`src/lockfile/build-infra-package-lock.json` when build-infra is installed from
159+
GitHub. npm does not include the root `package-lock.json` in installed Git
160+
packages. Whenever `package-lock.json` changes in this repository, refresh that
161+
snapshot too:
162+
163+
```sh
164+
npm run sync-lockfile-snapshot
165+
npm run check-lockfile-snapshot
166+
```
167+
168+
`npm test` also runs this check before the Vitest suite.
155169

156170
## Release Command Maintenance
157171

‎README.md‎

Lines changed: 13 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -158,7 +158,10 @@ npm ci
158158

159159
The command keeps the consumer repository's root package and resolved
160160
`@oai/build-infra` commit, then syncs the transitive dependency entries from the
161-
installed build-infra package lockfile.
161+
installed build-infra package lockfile snapshot. npm does not include a package's
162+
root `package-lock.json` when it installs a Git dependency, so build-infra keeps
163+
a packaged copy at `src/lockfile/build-infra-package-lock.json`. The test suite
164+
checks that this snapshot matches the repository's root `package-lock.json`.
162165

163166
## `spec.config.json`
164167

@@ -301,6 +304,14 @@ npm ci
301304
npm test
302305
```
303306

307+
When `package-lock.json` changes, refresh the packaged lockfile snapshot before
308+
committing. `npm test` runs the snapshot check automatically.
309+
310+
```sh
311+
npm run sync-lockfile-snapshot
312+
npm run check-lockfile-snapshot
313+
```
314+
304315
`npm test` runs self-contained tests. Some tests create temporary fixture
305316
specification repositories and local Git remotes so release-command behavior can
306317
be checked without a separate consumer repository.
@@ -316,7 +327,7 @@ regressions. Useful examples:
316327
| `tests/shell/bin-resolution.test.mjs` | How Markdown validation and formatting choose configs, when linkspector runs, and how command wrappers resolve hoisted binaries. |
317328
| `tests/release/release-commands.test.mjs` | The expected branch model for release commands, including clean-worktree and remote-branch guardrails. |
318329
| `tests/schema/schema-publish.test.mjs` | Schema publication behavior for source previews, versioned development branches, dated schema files, and Jekyll lander markdown. |
319-
| `tests/package/package-lock.test.mjs` | Lockfile entries that must exist for `npm ci` on GitHub-hosted Linux runners. |
330+
| `tests/package/package-lock.test.mjs` | Lockfile invariants, including keeping the packaged lockfile snapshot in sync with the root `package-lock.json`. |
320331
| `tests/lockfile/sync-consumer-lockfile.test.mjs` | How `oai-spec-sync-lockfile` repairs a consumer lockfile while preserving the resolved build-infra commit. |
321332
| `tests/package/exports.test.mjs` | Public helper modules that consumer test suites can import. |
322333

‎package.json‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,9 @@
3434
"./vitest-config": "./src/vitest-config.mjs"
3535
},
3636
"scripts": {
37-
"test": "vitest run"
37+
"check-lockfile-snapshot": "node src/lockfile/check-lockfile-snapshot.mjs",
38+
"sync-lockfile-snapshot": "cp package-lock.json src/lockfile/build-infra-package-lock.json",
39+
"test": "npm run check-lockfile-snapshot && vitest run"
3840
},
3941
"dependencies": {
4042
"@hyperjump/browser": "^1.0.0",

0 commit comments

Comments
 (0)