The `engines` field is advisory by default: an install run under an unpinned Node only emits a notice and still succeeds, so it rewrites package-lock.json with that older npm's resolution rules. That is not hypothetical — it happened while dropping the redundant platform bindings, and the resulting lockfile was rejected by `npm ci`. With engine-strict the mismatch is a hard failure instead, so the pin in .node-version is actually load-bearing for lockfile integrity. Verified: node 24 install now aborts with EBADENGINE, node 26 stays green (`npm run verify`, `npm ci` in sync), and npm auto-excludes .npmrc from the published tarball.
6 lines
310 B
Plaintext
6 lines
310 B
Plaintext
# Turn the `engines` field from a warning into a gate. By default a Node
|
|
# version mismatch is only reported as a notice, so an install run under an
|
|
# unpinned Node still succeeds and silently rewrites package-lock.json using
|
|
# that older npm's resolution rules. Refuse the install instead.
|
|
engine-strict=true
|