Skip to content

chore: remove unused root dependencies and lockfile (Issue 4) - #237

Open
Deepesh-Katudia wants to merge 2 commits into
mainfrom
chore/deps-root-cleanup
Open

Deepesh-Katudia wants to merge 2 commits into
mainfrom
chore/deps-root-cleanup

Conversation

@Deepesh-Katudia

Copy link
Copy Markdown
Collaborator

Summary

Strips the unused dependencies block from the root package.json and deletes the 2.5k-line root package-lock.json. Nothing at the repo root imports those packages; every service declares and installs its own. The root file stays for its --prefix convenience scripts and the volta Node pin.

Type of Change

  • New feature
  • Bug fix
  • Refactor
  • Documentation update
  • Style/UI update
  • Performance improvement
  • Other (please specify): dependency / security update (Issue 4)

Key Changes

  • Root package.json: removed chess.js, dotenv, express (^5), puppeteer-core, sass, socket.io. Scripts and volta pin untouched.
  • Root package-lock.json: deleted.
  • CI (.github/workflows/ci.yml): setup-node with cache: 'npm' looks for a lockfile at the repo root by default and fails the job when there is none. Added cache-dependency-path pointing at the four service lockfiles that npm ci actually installs from. Without this commit, deleting the root lockfile would break CI.

Testing

  • Unit tests added/updated
  • Integration tests added/updated
  • Manual testing performed: confirmed no root-level code consumes these deps; CI and scripts only install per-service with working-directory
  • All tests pass (CI on this PR is the real check for the cache-path change)

Bugs Fixed (if applicable)

  • Removes stale, unused dependency declarations that audit tooling and Dependabot were tracking at the root.

TODO (Follow-up Work)

  • Confirm the CI run on this PR restores/saves the npm cache without the "lock file is not found" error.

Additional Notes

Independent of the other Issue 4 PRs; can merge in any order.

sanjana1976 and others added 2 commits September 18, 2026 11:31
Nothing at the repo root imports chess.js, dotenv, express,
puppeteer-core, sass or socket.io; every service declares and installs
its own copies. The root file is kept only for its convenience
`--prefix` scripts and the volta Node pin, neither of which needs
installed dependencies, so the 2.5k-line root lockfile goes too.
setup-node's `cache: 'npm'` looks for a lockfile at the repo root by
default and fails the job when none exists. The root lockfile is gone,
so point cache-dependency-path at the four service lockfiles that
`npm ci` actually installs from.
Copilot AI lite review requested due to automatic review settings September 18, 2026 16:08

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The changes align with the repository’s per-service dependency structure and CI install paths.

Pull request overview

Removes unused root-level npm dependencies and lockfile while preserving per-service installs and fixing npm cache configuration in CI.

Changes:

  • Removed root dependency declarations.
  • Deleted the obsolete root lockfile.
  • Configured CI caching against the four service lockfiles it installs.
File summaries
File Description
package.json Retains root scripts and Volta pin without dependencies.
package-lock.json Removes stale root dependency resolution data.
.github/workflows/ci.yml Points npm caching to service lockfiles.
Review details
  • Files reviewed: 2/3 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants