Conversation
Releases ship their lockfile as npm-shrinkwrap.json. npm 12's npm ci refuses a package without a package-lock.json, so install.sh and install.ps1 failed with EUSAGE. Copy the shrinkwrap to package-lock.json before npm ci; older npm read the shrinkwrap first either way. Fixes AgentSystemLabs#278
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #278.
Why
Releases ship their dependency lockfile as
npm-shrinkwrap.json(release.yml copiespackage-lock.jsonto it beforenpm pack).npm ciin npm 12 only accepts apackage-lock.json, so with npm 12 the one-line install stops with:That's the failure in the issue (Fedora 44, Node 24.16, npm 12.0.2). I reproduced it with npm 12.2.0 against the current release tarball (v0.1.206):
install.shon maininstall.shwith this change(Both runs used
AGENT_OFFICE_TARBALL=<downloaded v0.1.206 agent-office.tgz> AGENT_OFFICE_INSTALL_ONLY=1.)What changed
install.sh: beforenpm ci, copy the release'snpm-shrinkwrap.jsontopackage-lock.jsonif the package doesn't already have one. Older npm already prefers the shrinkwrap, and the two files are identical, so they install exactly the same versions as before.install.ps1: the same copy in the Windows installer.tests/install.test.ts: runsinstall.shagainst a small local release tarball whose only lockfile isnpm-shrinkwrap.json. A stand-innpmonPATHbehaves like npm 12 (cifails withoutpackage-lock.json). The test checks thatnpm cisaw both files and that the version is installed and marked current.This is the same approach as the earlier #284, which its author closed without it being merged. This PR adds the regression test and the npm 12 reproduction above.
Verification
npm error The \npm ci` command can only install with an existing package-lock.json→agent-office: npm couldn't install Agent Office's dependencies`) and passes with the change.npm run typecheck: passesnpm test: 607 tests, 607 passnpm run build: passesbash -n install.sh: passesNot tested:
install.ps1on Windows. I don't have PowerShell or Windows here, so that part has only been reviewed by reading it; it mirrors the bash change line for line.