Repository navigation
69 lines (56 loc) · 2.67 KB
/
Copy pathpackage-lock-lint.yml
File metadata and controls
69 lines (56 loc) · 2.67 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
name: Package lock lint
# This workflow catches manual package.json edits that leave package-lock.json out of sync.
# It also blocks Microsoft package feed URLs, which break installs outside GitHub.
on:
pull_request:
paths:
- .npmrc
- package.json
- package-lock.json
- .github/workflows/package-lock-lint.yml
permissions:
contents: read
# Cancel older runs for the same PR because this check only depends on the latest commit.
concurrency:
group: '${{ github.workflow }} @ ${{ github.event.pull_request.head.label || github.head_ref || github.ref }}'
cancel-in-progress: true
jobs:
lint:
runs-on: ubuntu-latest
if: github.repository == 'github/docs-internal' || github.repository == 'github/docs'
steps:
- name: Check out repo
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- name: Check for package feed URLs
run: |
status=0
grep -inE 'https?://[^/"]*(pkgs\.visualstudio\.com|pkgs\.dev\.azure\.com|packagefeedproxy\.microsoft\.io)' .npmrc package-lock.json || status=$?
if [ "$status" -eq 0 ]; then
echo "::error::Found Microsoft package feed URLs. Use https://registry.npmjs.org/ instead."
exit 1
elif [ "$status" -ne 1 ]; then
echo "::error::Could not scan .npmrc and package-lock.json for package feed URLs."
exit "$status"
fi
- name: Setup Node.js
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version-file: 'package.json'
cache: npm
- name: Run check
run: |
npm --version
node -e "console.log(JSON.stringify(require('./package-lock.json').packages['']))" > /tmp/before.json
# npm install --package-lock-only updates package-lock.json
# without checking node_modules or downloading packages.
# See https://docs.npmjs.com/cli/v7/commands/npm-install.
npm install --package-lock-only --ignore-scripts --include=optional
node -e "console.log(JSON.stringify(require('./package-lock.json').packages['']))" > /tmp/after.json
# Compare only top-level package dependencies because platform-specific nested dependency
# metadata, such as peer flags, does not affect actual installed versions.
if ! diff /tmp/before.json /tmp/after.json; then
echo "ERROR: Top-level dependencies in package-lock.json are out of sync with package.json"
echo "Please run 'npm install' locally and commit the updated package-lock.json"
exit 1
fi
echo "✓ Top-level dependencies are in sync"