-
Notifications
You must be signed in to change notification settings - Fork 1
[CDX-610] fix react-compat ci failing #57
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
niizom
merged 1 commit into
main
from
cdx-610-components-ui-investigate-and-fix-react-compat-ci-failing-on
Aug 27, 2026
Merged
Changes from all commits
Commits
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -36,7 +36,7 @@ jobs: | |
| mv "${tarballs[0]}" constructorio-ui-components.tgz | ||
| - name: Install fixture deps | ||
| working-directory: test/react-compat/${{ matrix.react-major }} | ||
| run: npm ci --no-audit --no-fund | ||
| run: npm install --no-audit --no-fund --package-lock=false | ||
|
Contributor
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. npm install still reads the lock file and enforces its integrity hashes. So it fails with the same EINTEGRITY error as npm ci when the tarball hash doesn't match. |
||
| - name: Typecheck fixture | ||
| working-directory: test/react-compat/${{ matrix.react-major }} | ||
| run: npm run typecheck | ||
|
|
||
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Important Issue: Switching to
npm install --package-lock=falseresolves the immediatenpm cifailure, but it fully bypasses lock-file pinning for all transitive dependencies (not just the local tarball). This means every CI run resolves the latest versions of all deps from the registry, which can introduce silent breakages from transitive dependency upgrades.A more precise fix would be to use
npm install --no-audit --no-fund(without--package-lock=false) and ensure the fixturepackage-lock.jsonfiles do not commit a resolved entry for the local tarball path. Alternatively, you can keep--package-lock=falsebut add a--prefer-offlineflag and a caching step so at least the registry packages are stable between runs.If the intent is specifically to avoid
npm cifailing due to the regenerated tarball hash, consider usingnpm ci --ignore-scriptscombined with a separatenpm install <local-tarball>step, or patching the lock file before runningnpm ci(e.g.,npm install --package-lock-onlyto regenerate the lock file beforenpm ci).The current change is pragmatic and unblocks CI, but the lack of lock-file enforcement for transitive deps reduces reproducibility for a test matrix that exists specifically to catch subtle compatibility issues.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Good point. But this is not an issue here cause we are using exact versions of a libraries so everything will be fine