18 lines
656 B
Plaintext
18 lines
656 B
Plaintext
# MIBP fork — npm behavior pin.
|
|||
|
|
#
|
||
|
|
# DO NOT DELETE. See AGENTS.md §1.
|
||
|
|
#
|
||
|
|
# The Docker image (node:22-alpine, pinned by digest) ships npm 10.9.8 and runs
|
||
|
|
# `npm ci` against the committed package-lock.json. Regenerating the lockfile
|
||
|
|
# with npm 11+ drops the top-level @emnapi/core + @emnapi/runtime entries npm 10
|
||
|
|
# needs, which breaks the tag-triggered Docker build ("Build and Push Docker
|
||
|
|
# Image") at `npm ci`.
|
||
|
|
#
|
||
|
|
# Regenerate the lockfile with npm 10 only:
|
||
|
|
# npx -y npm@10.9.8 install --package-lock-only
|
||
|
|
# node scripts/verify-lockfile-npm10.mjs
|
||
|
|
#
|
||
|
|
# Keep install output quiet; never let audit/fund noise hide a lockfile error.
|
||
|
|
audit=false
|
||
|
|
fund=false
|