Skip to content

chore: remove unused package-lock.json files - #9713

Merged
taylorsilva merged 1 commit into
concourse:masterfrom
alicul:cleanup-npm-locks
Oct 2, 2026
Merged

taylorsilva merged 1 commit into
concourse:masterfrom
alicul:cleanup-npm-locks

Conversation

@alicul

@alicul alicul commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

The repository standardizes on Yarn v4 (yarn@4.14.1 via packageManager) and uses yarn.lock for dependency resolution in both root and web/wats. All build scripts, CI tasks, and developer workflows exclusively use Yarn.

Why these files can be safely removed:

  1. Root package-lock.json was added in bc30fec under the assumption it was needed after the Yarn v4 upgrade, while web/wats/package-lock.json was accidentally committed in 2021 (c936fe5). Neither is consumed by any tool or pipeline.
  2. Their presence causes automated dependency tooling (Renovate) to detect npm alongside Yarn and attempt dual lockfile updates. This triggers npm ERESOLVE peer dependency errors (e.g. PR fix(deps): update javascript #9561 with Babel 8) and blocks automated dependency updates.

Also adds package-lock.json to .gitignore to prevent accidental re-commits.

Thanks to @pjurczynski for double checking this for me..

The repository standardizes on Yarn v4 (yarn@4.14.1 via packageManager)
and uses yarn.lock for dependency resolution in both root and web/wats.
All build scripts, CI tasks, and developer workflows exclusively use Yarn.

Why these files can be safely removed:
1. Root package-lock.json was added in bc30fec under the assumption it
   was needed after the Yarn v4 upgrade, while web/wats/package-lock.json
   was accidentally committed in 2021 (c936fe5). Neither is consumed by
   any tool or pipeline.
2. Their presence causes automated dependency tooling (Renovate) to detect
   npm alongside Yarn and attempt dual lockfile updates. This triggers
   npm ERESOLVE peer dependency errors (e.g. PR concourse#9561 with Babel 8) and
   blocks automated dependency updates.

Also adds package-lock.json to .gitignore to prevent accidental re-commits.
@taylorsilva taylorsilva added release/undocumented This didn't warrant being documented or put in release notes. misc labels Sep 10, 2026

@taylorsilva taylorsilva left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Will merge once all checks pass.

@taylorsilva taylorsilva moved this from Todo to In Progress in Pull Requests Sep 10, 2026
@taylorsilva
taylorsilva merged commit 9a90155 into concourse:master Oct 2, 2026
11 checks passed
@github-project-automation github-project-automation Bot moved this from In Progress to Done in Pull Requests Oct 2, 2026
@alicul
alicul deleted the cleanup-npm-locks branch October 3, 2026 21:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

misc release/undocumented This didn't warrant being documented or put in release notes.

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants