npm / npm/cli

[BUG] ERESOLVE error because only latest version in peer dependency range is respected in dep resolution

Open
#7,022 8 comments 2 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Bug Needs Triage Release 10.x
Dominant language
JavaScript
Stars
10.1k
Forks
4.7k
Avg merge
2d 2h
Merged PRs (30d)
19

Description

Is there an existing issue for this?
  • I have searched the existing issues

Potentially related issues:

  • #4104: almost the same but involves multiple direct dependencies
  • #4442: similar but not only involves peer dependencies
This issue exists in the latest npm version
  • I am using the latest npm
Current Behavior

I'm installing a package with peer dependencies. These peer dependencies are given in ranges. During the dependency resolution only the latest version of each of these ranges is respected, so compatible non-latest versions that would satisfy the given ranges are dismissed.


An example:

This bug report is based on a package called @aposin/ng-aquila in version 16.10.0, but this is reproducible with a lot of other packages as well. The problem is always the same.

image

Deciphered error message:

  1. the package @aposin/ng-aquila@16.10.0 has a peer dependency to @angular/core@^16.0.0. This resolves to the latest version in the allowed range: @angular/core@16.2.12
  2. the package @aposin/ng-aquila@16.10.0 also has a peer dependency to @angular/cdk@^16.0.0. This resolves to the latest version in the given range: @angular/cdk@16.2.12
  3. the package @angular/cdk@16.2.12 has a peer dependency to @angular/common@^16.0.0 || ^17.0.0. This resolves to the latest version in that range: @angular/common@17.0.4
  4. the package @angular/common@17.0.4 has a peer dependency to @angular/core@17.0.4 which conflicts with @angular/core@16.2.12 that was found in step 1, leading to an ERESOLVE error
Expected Behavior

The dependency @angular/common@^16.0.0 || ^17.0.0 should have been resolved to a version that specifies a peer dependency that is compatible with the other found peer dependencies. npm only looks at the latest version in that range and dismisses the matching versions that would satisfy all specified dependency ranges. In this case, installing version 16.x for the range @angular/common@^16.0.0 || ^17.0.0 would have led to @angular/core@16.2.12 which satisfies all dependency ranges.

Steps To Reproduce
  1. Create a new folder and run npm init -y to create a new package.json without any dependencies
  2. Run npm install @aposin/ng-aquila@16.10.0
  3. See the ERESOLVE error
Environment
  • npm: 10.2.3
  • Node.js: 21.2.0
  • OS Name: Ubuntu 20.04
  • System Model Name:
  • npm config:
; node bin location = </some/path>
; node version = v21.2.0
; npm local prefix = </some/path>
; npm version = 10.2.3
; cwd = </some/path>
; HOME = </some/path>
; Run `npm config ls -l` to show all defaults.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Reproduce the failure in a new folder with npm init -y followed by npm install @aposin/ng-aquila@16.10.0, using the reported npm and Node versions if available. Trace peer-dependency resolution from the ERESOLVE output and compare the selected latest versions with the compatible 16.x alternative. Done means npm installs the package by selecting peer versions that satisfy all listed ranges without ERESOLVE.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript, node.js
Domain
cli, devtools
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
32/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.