Repository navigation
Chore: commit the lockfile, run npm ci, and drop two dead files - #15
Merged
Merged
Conversation
package-lock.json was explicitly listed in .gitignore, and CI ran npm install. Every CI run and every Netlify deploy therefore resolved the dependency tree afresh inside the ^ ranges in package.json: react 19, react-dom, recharts 3, vite 6, tailwind 4 and @vitejs/plugin-react. A build that passed yesterday could fail today with no commit in between, and a compromised transitive release would land with nothing to notice it. That exclusion is an outlier rather than a house policy: seven of the nine Node repositories in this estate track a lockfile, and only this one ignored it. - Generate and commit package-lock.json, and remove the .gitignore line with a note saying why it is committed. - CI switches from npm install to npm ci, which installs exactly what the lockfile records and fails if the lockfile and package.json disagree. - Bump actions/checkout v4 to v6 and actions/setup-node v4 to v5, and enable the npm cache now that there is a lockfile to key it on. Audited while generating it: 0 vulnerabilities. Build verified before and after, and again after the deletions below. Also deletes two files that were doing nothing: - src/App_BackUp.js, 534 lines against App.jsx's 753, imported by nothing. Vite never bundled it, but it read as a second copy of the application. It remains in the git history. - src/.DS_Store, a committed macOS artifact. .gitignore now covers it. Adds CLAUDE.md, which records the lockfile reasoning and one thing worth knowing: the lychee link check runs with fail: false, so a dead external link is reported and the job stays green. Defensible for a third-party crawl, but a green CI here does not mean the links are good. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MrvR2NXsJFVRCeJZFCPuNL
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
package-lock.jsonwas explicitly listed in.gitignore(line 39), and CI rannpm install.So every CI run and every Netlify deploy resolved the dependency tree afresh inside the
^ranges inpackage.json— react 19, react-dom, recharts 3, vite 6, tailwind 4, @vitejs/plugin-react. A build that passed yesterday could fail today with no commit in between, and a compromised transitive release would land with nothing to notice it.That exclusion looks like a decision, so I checked whether it was house policy. It isn't: seven of the nine Node repositories in this estate track a lockfile. This one is the only outlier.
If you excluded it deliberately and want it back out, say so and I'll revert — but for a deployed application rather than a published library, committing it is the convention your own estate already follows.
Changes
package-lock.json; remove the.gitignoreline, replaced with a note saying why it is committed.npm install→npm ci, which installs exactly what the lockfile records and fails if the lockfile andpackage.jsondisagree.actions/checkoutv4 → v6,actions/setup-nodev4 → v5, and the npm cache enabled now that there is a lockfile to key it on.npm audit: 0 vulnerabilities. Build verified before the change, after it, and again after the deletions below.Two dead files removed
src/App_BackUp.js— 534 lines againstApp.jsx's 753, imported by nothing. Vite never bundled it, so it shipped nothing, but it read as a second copy of the application. Still in git history.src/.DS_Store— a committed macOS artifact..gitignorenow covers it.One thing flagged, not changed
.github/workflows/ci.ymlrunslycheeverse/lychee-actionwithfail: false, so a dead external link is reported and the job stays green. That is defensible for a third-party link crawl — a link can rot with no commit behind it — but a green CI here does not mean the links are good. Noted inCLAUDE.mdrather than changed, since making it blocking would fail builds for reasons outside this repo's control.Generated by Claude Code