Skip to content

Repo sync

Repo sync #2458

name: Package lock lint
# This workflow catches manual package.json edits that leave package-lock.json out of sync.
on:
pull_request:
paths:
- package.json
- package-lock.json
- .github/workflows/package-lock-lint.yml
permissions:
contents: read
# Cancel older runs for the same PR because this check only depends on the latest commit.
concurrency:
group: '${{ github.workflow }} @ ${{ github.event.pull_request.head.label || github.head_ref || github.ref }}'
cancel-in-progress: true
jobs:
lint:
runs-on: ubuntu-latest
if: github.repository == 'github/docs-internal' || github.repository == 'github/docs'
steps:
- name: Check out repo
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- name: Setup Node.js
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version-file: 'package.json'
cache: npm
- name: Run check
run: |
npm --version
node -e "console.log(JSON.stringify(require('./package-lock.json').packages['']))" > /tmp/before.json
# npm install --package-lock-only updates package-lock.json
# without checking node_modules or downloading packages.
# See https://docs.npmjs.com/cli/v7/commands/npm-install.
npm install --package-lock-only --ignore-scripts --include=optional
node -e "console.log(JSON.stringify(require('./package-lock.json').packages['']))" > /tmp/after.json
# Compare only top-level package dependencies because platform-specific nested dependency
# metadata, such as peer flags, does not affect actual installed versions.
if ! diff /tmp/before.json /tmp/after.json; then
echo "ERROR: Top-level dependencies in package-lock.json are out of sync with package.json"
echo "Please run 'npm install' locally and commit the updated package-lock.json"
exit 1
fi
echo "✓ Top-level dependencies are in sync"