Skip to content

Fix dependencies with missing resolved in lockfile - #2296

Open
eljamm wants to merge 1 commit into
cryptpad:stagingfrom
eljamm:fix-lockfile
Open

eljamm wants to merge 1 commit into
cryptpad:stagingfrom
eljamm:fix-lockfile

Conversation

@eljamm

@eljamm eljamm commented May 15, 2026

Copy link
Copy Markdown

This change regenerates the lockfile to fix the missing resolved fields:

rm package-lock.json & npm install --package-lock-only --ignore-scripts

Which causes issues while building Cryptpad in reproducible environments, for example when updating in Nixpkgs:

warning: 313 out of 483 packages (64.8%) are missing 'resolved' URLs and will not be cached.
warning: Packages without 'resolved' URLs:
warning:   - jwa
warning:   - safer-buffer
warning:   - methods
warning:   - minitask
warning:   - buffer-from
warning:   - looper
warning:   - @node-saml/node-saml
warning:   - jszip/node_modules/safe-buffer
warning:   - accepts
warning:   - gluejs/node_modules/resolve
warning:   ... and 303 more
warning: More than 50% of packages are missing 'resolved' URLs. This may indicate an issue with the lockfile.
warning: This is a known issue with some npm versions. See: https://github.com/npm/cli/issues/6301
warning: Consider regenerating upstream's lockfile with: npm install --package-lock-only (sending an upstream PR is best)

@davidbenque davidbenque added this to the Summer Release (2026.6.0) milestone May 15, 2026
@davidbenque davidbenque added the Ready to Review This PR is ready to be checked by another team member label May 15, 2026
@davidbenque
davidbenque changed the base branch from main to staging May 26, 2026 15:38
@eljamm

eljamm commented Jun 1, 2026

Copy link
Copy Markdown
Author

Resolved merge conflict.

@martinetd

Copy link
Copy Markdown
Contributor

Hi @davidbenque , thanks for the review & fixing the branch to staging last month

@yflory , would you be able to have a second look so this could get unstuck? I assume 2026.6 is just around the corner and it'd be great to fix this so we can update the nixpkgs package :)
(sorry for the direct ping, you merged my PRs in the past)

@Chouhartem

Copy link
Copy Markdown
Contributor

Hello,

Sorry for the late reply but we will integrate these changes in the next release :)

This change regenerates the lockfile to fix the missing `resolved`
fields:

```shellSession
rm package-lock.json & npm install --package-lock-only --ignore-scripts
```

Which causes issues while building Cryptpad in reproducible environments,
for example when [updating in Nixpkgs](NixOS/nixpkgs#511890):

```shellSession
warning: 313 out of 483 packages (64.8%) are missing 'resolved' URLs and will not be cached.
warning: Packages without 'resolved' URLs:
warning:   - jwa
warning:   - safer-buffer
warning:   - methods
warning:   - minitask
warning:   - buffer-from
warning:   - looper
warning:   - @node-saml/node-saml
warning:   - jszip/node_modules/safe-buffer
warning:   - accepts
warning:   - gluejs/node_modules/resolve
warning:   ... and 303 more
warning: More than 50% of packages are missing 'resolved' URLs. This may indicate an issue with the lockfile.
warning: This is a known issue with some npm versions. See: npm/cli#6301
warning: Consider regenerating upstream's lockfile with: npm install --package-lock-only (sending an upstream PR is best)
```
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Ready to Review This PR is ready to be checked by another team member

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants