Skip to content

Chore: commit the lockfile, run npm ci, and drop two dead files - #15

Merged
Varnasr merged 1 commit into
mainfrom
claude/outdated-repos-maintenance-nbxnae
Sep 22, 2026
Merged

Varnasr merged 1 commit into
mainfrom
claude/outdated-repos-maintenance-nbxnae

Conversation

@Varnasr

@Varnasr Varnasr commented Sep 22, 2026

Copy link
Copy Markdown
Owner

package-lock.json was explicitly listed in .gitignore (line 39), and CI ran npm install.

So every CI run and every Netlify deploy resolved the dependency tree afresh inside the ^ ranges in package.json — react 19, react-dom, recharts 3, vite 6, tailwind 4, @vitejs/plugin-react. A build that passed yesterday could fail today with no commit in between, and a compromised transitive release would land with nothing to notice it.

That exclusion looks like a decision, so I checked whether it was house policy. It isn't: seven of the nine Node repositories in this estate track a lockfile. This one is the only outlier.

If you excluded it deliberately and want it back out, say so and I'll revert — but for a deployed application rather than a published library, committing it is the convention your own estate already follows.

Changes

  • Generate and commit package-lock.json; remove the .gitignore line, replaced with a note saying why it is committed.
  • CI: npm install → npm ci, which installs exactly what the lockfile records and fails if the lockfile and package.json disagree.
  • actions/checkout v4 → v6, actions/setup-node v4 → v5, and the npm cache enabled now that there is a lockfile to key it on.

npm audit: 0 vulnerabilities. Build verified before the change, after it, and again after the deletions below.

Two dead files removed

  • src/App_BackUp.js — 534 lines against App.jsx's 753, imported by nothing. Vite never bundled it, so it shipped nothing, but it read as a second copy of the application. Still in git history.
  • src/.DS_Store — a committed macOS artifact. .gitignore now covers it.

One thing flagged, not changed

.github/workflows/ci.yml runs lycheeverse/lychee-action with fail: false, so a dead external link is reported and the job stays green. That is defensible for a third-party link crawl — a link can rot with no commit behind it — but a green CI here does not mean the links are good. Noted in CLAUDE.md rather than changed, since making it blocking would fail builds for reasons outside this repo's control.


Generated by Claude Code

package-lock.json was explicitly listed in .gitignore, and CI ran npm install.
Every CI run and every Netlify deploy therefore resolved the dependency tree
afresh inside the ^ ranges in package.json: react 19, react-dom, recharts 3,
vite 6, tailwind 4 and @vitejs/plugin-react. A build that passed yesterday could
fail today with no commit in between, and a compromised transitive release would
land with nothing to notice it.

That exclusion is an outlier rather than a house policy: seven of the nine Node
repositories in this estate track a lockfile, and only this one ignored it.

- Generate and commit package-lock.json, and remove the .gitignore line with a
  note saying why it is committed.
- CI switches from npm install to npm ci, which installs exactly what the
  lockfile records and fails if the lockfile and package.json disagree.
- Bump actions/checkout v4 to v6 and actions/setup-node v4 to v5, and enable the
  npm cache now that there is a lockfile to key it on.

Audited while generating it: 0 vulnerabilities. Build verified before and after,
and again after the deletions below.

Also deletes two files that were doing nothing:

- src/App_BackUp.js, 534 lines against App.jsx's 753, imported by nothing. Vite
  never bundled it, but it read as a second copy of the application. It remains
  in the git history.
- src/.DS_Store, a committed macOS artifact. .gitignore now covers it.

Adds CLAUDE.md, which records the lockfile reasoning and one thing worth knowing:
the lychee link check runs with fail: false, so a dead external link is reported
and the job stays green. Defensible for a third-party crawl, but a green CI here
does not mean the links are good.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MrvR2NXsJFVRCeJZFCPuNL
@Varnasr
Varnasr merged commit 52a550e into main Sep 22, 2026
1 check passed
@Varnasr
Varnasr deleted the claude/outdated-repos-maintenance-nbxnae branch September 22, 2026 23:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants