From 682ecf1163d0f39d7cf35eb13dad462debe7e10c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Thomas=20M=C3=BCller?= Date: Sun, 6 Sep 2026 00:13:12 +0200 Subject: [PATCH] :sparkles: Enforce pinned Node via engine-strict MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The `engines` field is advisory by default: an install run under an unpinned Node only emits a notice and still succeeds, so it rewrites package-lock.json with that older npm's resolution rules. That is not hypothetical — it happened while dropping the redundant platform bindings, and the resulting lockfile was rejected by `npm ci`. With engine-strict the mismatch is a hard failure instead, so the pin in .node-version is actually load-bearing for lockfile integrity. Verified: node 24 install now aborts with EBADENGINE, node 26 stays green (`npm run verify`, `npm ci` in sync), and npm auto-excludes .npmrc from the published tarball. --- .npmrc | 5 +++++ 1 file changed, 5 insertions(+) create mode 100644 .npmrc diff --git a/.npmrc b/.npmrc new file mode 100644 index 0000000..fcbc875 --- /dev/null +++ b/.npmrc @@ -0,0 +1,5 @@ +# Turn the `engines` field from a warning into a gate. By default a Node +# version mismatch is only reported as a notice, so an install run under an +# unpinned Node still succeeds and silently rewrites package-lock.json using +# that older npm's resolution rules. Refuse the install instead. +engine-strict=true