ci: use locked ESM smoke dependencies - #11128
Conversation
There was a problem hiding this comment.
Pull request overview
This PR aims to stabilize CI by making the ESM smoke test dependency installation deterministic, ensuring the ESM smoke suite uses the committed lockfile rather than resolving dependencies at install time.
Changes:
- Updated
tests/smoke/esm/package-lock.jsonto lock updated ESM smoke test tooling dependencies (notablyvitest). - Switched the ESM smoke workflow step from
npm installtonpm cito enforce lockfile-based installs in CI.
Reviewed changes
Copilot reviewed 1 out of 2 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
| tests/smoke/esm/package-lock.json | Updates locked dependency graph for the ESM smoke test workspace (including vitest bump). |
| .github/workflows/run-ci.yml | Uses npm ci for ESM smoke dependency install to ensure reproducible CI runs. |
Files not reviewed (1)
- tests/smoke/esm/package-lock.json: Generated file
Greptile SummaryThis change makes ESM smoke-test dependency installation reproducible by using the checked-in lockfile with The ESM smoke path was checked by building and packing axios locally, installing the packed tarball in the ESM workspace after Confidence Score: 5/5
What T-Rex did
Reviews (1): Last reviewed commit: "Merge branch 'v1.x' into fix/esm-smoke-n..." | Re-trigger Greptile |
Summary
Fixes CI runs
Linked issue
N/A
Changes
N/A
Checklist
index.d.tsandindex.d.cts)Summary by cubic
Lock ESM smoke test dependencies and switch CI to use npm ci for deterministic installs on npm 10, reducing flakiness in ESM smoke runs. Updates the
tests/smoke/esmlockfile to pin versions and align with newervite/rolldown.Description
Summary of changes
npm installwithnpm ci --ignore-scriptsfortests/smoke/esm.tests/smoke/esm/package-lock.jsonto lock deps (e.g.vitest@4.1.9,vite@8.2.0,rolldown@1.2.2,lightningcss@1.33.0,postcss@8.5.25).@rolldown/*native bindings to1.2.2; remove wasm/emnapioptional deps from the lockfile.Reasoning
npm cienforces reproducible installs under npm 10 and prevents drift from upstream minor releases.vite/rolldownmatch current engines and stabilize the ESM smoke build.Additional context
tests/smoke/esmfixture; no runtime or public API changes.Docs
/docs/(e.g., contributing/CI) that smoke test fixtures should be installed withnpm ci --ignore-scriptsand keep their lockfiles committed.Testing
Semantic version impact
Written for commit fd747ca. Summary will update on new commits.