Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update package-lock.json format? #1658

Closed
shadowspawn opened this issue Dec 21, 2021 · 1 comment
Closed

Update package-lock.json format? #1658

shadowspawn opened this issue Dec 21, 2021 · 1 comment

Comments

@shadowspawn
Copy link
Collaborator

Node.js v14 includes npm 6.14.15 which writes package-lock.json with lockfileVersion@1 format.

Node.js v16 includes npm 8.1.2 which writes package-lock.json with lockfileVersion@2 format.

Changing versions is noisy. Node.js v14 is still in LTS but now in maintenance mode.

I am leaning towards switching to lockfileVersion@2 for Commander v9 so more convenient to develop Commander with Node.js v16 installed?


Installing using old lock file and new npm:

my-fork % n lts
   installed : v16.13.1 (with npm 8.1.2)
my-fork % npm install
npm WARN old lockfile 
npm WARN old lockfile The package-lock.json file was created with an old version of npm,
npm WARN old lockfile so supplemental metadata must be fetched from the registry.
npm WARN old lockfile 
npm WARN old lockfile This is a one-time fix-up, please be patient...
npm WARN old lockfile 

changed 1 package, and audited 696 packages in 10s

94 packages are looking for funding
  run `npm fund` for details

7 moderate severity vulnerabilities

To address all issues, run:
  npm audit fix

Run `npm audit` for details.

Installing using new lock file and old npm:

my-fork % n 14
   installed : v14.18.2 (with npm 6.14.15)
my-fork % npm install
npm WARN read-shrinkwrap This version of npm is compatible with lockfileVersion@1, but package-lock.json was generated for lockfileVersion@2. I'll try to do my best with it!
updated 1 package and audited 696 packages in 3.862s

94 packages are looking for funding
  run `npm fund` for details

found 18 moderate severity vulnerabilities
  run `npm audit fix` to fix them, or `npm audit` for details
@shadowspawn shadowspawn added the pending release Merged into a branch for a future release, but not released yet label Dec 21, 2021
@shadowspawn shadowspawn added this to the Commander v9.0.0 milestone Dec 21, 2021
@shadowspawn
Copy link
Collaborator Author

Commander v9 has been released.

@shadowspawn shadowspawn removed the pending release Merged into a branch for a future release, but not released yet label Jan 29, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant