jaredly / jaredly/reprocessing-example-cross-platform
package-lock.json can lead to installation errors
- 主要言語
- OCaml
- スター
- 50
- フォーク
- 5
- PR マージ指標
- 30日以内にマージされた PR はありません
説明
I've noticed a problem with re-installing `node_modules` multiple times with the generated `package-lock.json` file. It seems to stem from various dependencies using different versions of the `bs-platform` package; when installing initially all dependencies install `bs-platform@2.1.1`. Later installation attempts using the `package-lock` will download conflicting versions of that package (`matchenv` uses `bs-platform@3.2.0`, whereas `reprocessing-scripts` still gets `bs-platform@2.1.1`). This seems to cause an error during installation due to missing files in `bs-platform`.
What can I do to get a consistent build without deleting `package-lock.json` every time I run `npm i`? Is there a way to force all of the dependencies to use the same `bs-platform`?
**Reproduction steps:**
1. delete `package-lock.json` (and anything in `node_modules`) and run `npm i`, all of the necessary dependencies will install correctly and a new `package-lock` will be generated.
2. delete all of the `node_modules` and re-install (`npm i`), the installation will succeed (with several duplicated package warnings), but `package-lock` will be updated again.
3. Deleting `node_modules` a third time and attempting to reinstall leads to the following error output:
```
ppx-env@1.0.0 postinstall /Users/luke/git/project/node_modules/ppx-env
bsb && cp lib/bs/native/ppx.native ppx-env
Error: spawnSync /Users/luke/git/project/node_modules/ppx-env/node_modules/bs-platform/lib/bsb.exe ENOENT
npm ERR! code ELIFECYCLE
npm ERR! errno 2
npm ERR! ppx-env@1.0.0 postinstall: `bsb && cp lib/bs/native/ppx.native ppx-env`
npm ERR! Exit status 2
npm ERR!
npm ERR! Failed at the ppx-env@1.0.0 postinstall script.
npm ERR! This is probably not a problem with npm. There is likely additional logging output above.
npm ERR! A complete log of this run can be found in:
npm ERR! /Users/luke/.npm/_logs/2018-07-12T20_04_12_189Z-debug.log
```
`package-lock.json` is supposed to make builds reproducible, so I don't understand what's causing this problem. Thank you for any advice or insight you may be able to provide.
コントリビューションガイド
このリポジトリのコントリビューションガイドは索引されていません
調査の方向性
まず、package-lock.json と node_modules を使って3回のインストール手順を再現し、次に bs-platform、matchenv、reprocessing-scripts、ppx-env の依存関係エントリを調べます。ppx-env の postinstall コマンドと、存在しない bs-platform/lib/bsb.exe パスを確認します。完了とは、クリーンな npm i の実行を繰り返しても、報告されている ENOENT や予期しない lockfile の変更が発生せず、常に一貫して成功することです。
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- node.js, ocaml
- 領域
- build-system, tooling
- issue の種類
- バグ
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 活発さ
- 停滞
- 明瞭さ
- おおむね明確
- 初心者へのやさしさ
- 42/100