jaredly / jaredly/reprocessing-example-cross-platform
package-lock.json can lead to installation errors
- 主要语言
- OCaml
- 星标
- 50
- 派生
- 5
- PR 合并指标
- 30 天内没有已合并 PR
描述
I've noticed a problem with re-installing `node_modules` multiple times with the generated `package-lock.json` file. It seems to stem from various dependencies using different versions of the `bs-platform` package; when installing initially all dependencies install `bs-platform@2.1.1`. Later installation attempts using the `package-lock` will download conflicting versions of that package (`matchenv` uses `bs-platform@3.2.0`, whereas `reprocessing-scripts` still gets `bs-platform@2.1.1`). This seems to cause an error during installation due to missing files in `bs-platform`.
What can I do to get a consistent build without deleting `package-lock.json` every time I run `npm i`? Is there a way to force all of the dependencies to use the same `bs-platform`?
**Reproduction steps:**
1. delete `package-lock.json` (and anything in `node_modules`) and run `npm i`, all of the necessary dependencies will install correctly and a new `package-lock` will be generated.
2. delete all of the `node_modules` and re-install (`npm i`), the installation will succeed (with several duplicated package warnings), but `package-lock` will be updated again.
3. Deleting `node_modules` a third time and attempting to reinstall leads to the following error output:
```
ppx-env@1.0.0 postinstall /Users/luke/git/project/node_modules/ppx-env
bsb && cp lib/bs/native/ppx.native ppx-env
Error: spawnSync /Users/luke/git/project/node_modules/ppx-env/node_modules/bs-platform/lib/bsb.exe ENOENT
npm ERR! code ELIFECYCLE
npm ERR! errno 2
npm ERR! ppx-env@1.0.0 postinstall: `bsb && cp lib/bs/native/ppx.native ppx-env`
npm ERR! Exit status 2
npm ERR!
npm ERR! Failed at the ppx-env@1.0.0 postinstall script.
npm ERR! This is probably not a problem with npm. There is likely additional logging output above.
npm ERR! A complete log of this run can be found in:
npm ERR! /Users/luke/.npm/_logs/2018-07-12T20_04_12_189Z-debug.log
```
`package-lock.json` is supposed to make builds reproducible, so I don't understand what's causing this problem. Thank you for any advice or insight you may be able to provide.
贡献指南
这个仓库没有索引到贡献指南
调研方向
首先使用 package-lock.json 和 node_modules 重现三次安装的顺序,然后检查 bs-platform、matchenv、reprocessing-scripts 和 ppx-env 的依赖项。检查 ppx-env 的 postinstall 命令以及缺失的 bs-platform/lib/bsb.exe 路径;当重复执行干净的 npm i 时始终一致,且不再出现报告中的 ENOENT 或意外的 lockfile 更改时,即表示完成。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- node.js, ocaml
- 领域
- build-system, tooling
- Issue 类型
- 缺陷
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 活跃度
- 停滞
- 描述清晰度
- 基本清楚
- 新手友好度
- 42/100