✨ Enforce pinned Node via engine-strict
The `engines` field is advisory by default: an install run under an unpinned Node only emits a notice and still succeeds, so it rewrites package-lock.json with that older npm's resolution rules. That is not hypothetical — it happened while dropping the redundant platform bindings, and the resulting lockfile was rejected by `npm ci`. With engine-strict the mismatch is a hard failure instead, so the pin in .node-version is actually load-bearing for lockfile integrity. Verified: node 24 install now aborts with EBADENGINE, node 26 stays green (`npm run verify`, `npm ci` in sync), and npm auto-excludes .npmrc from the published tarball.
This commit is contained in:
1 parent
8b4722da26
commit
682ecf1163
1 file changed
+5
@@ -0,0 +1,5 @@
|
||||
# Turn the `engines` field from a warning into a gate. By default a Node
|
||||
# version mismatch is only reported as a notice, so an install run under an
|
||||
# unpinned Node still succeeds and silently rewrites package-lock.json using
|
||||
# that older npm's resolution rules. Refuse the install instead.
|
||||
engine-strict=true
|
||||
Reference in new issue
Block a user