Skip to content

feat(lint): enforce yarn.lock as the only Node.js lockfile - #1221

Merged
malept merged 11 commits into
mainfrom
malept-claude/relaxed-brown-xkfa7z
Sep 29, 2026
Merged

malept merged 11 commits into
mainfrom
malept-claude/relaxed-brown-xkfa7z

Conversation

@malept

@malept malept commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

What this PR does / why we need it

Node.js dependencies in Stenciled repos are standardized on Yarn. Adds shell/linters/nodejs-lockfile.sh to the built-in linter set, covering the repo root and api/clients/node (stencil's generated gRPC Node.js client) — the only two locations where stencil manages a Node.js package.json:

  • Fails if package-lock.json, npm-shrinkwrap.json, pnpm-lock.yaml, bun.lock, or bun.lockb is present in either directory.
  • Fails if either directory has a package.json without a committed yarn.lock.

The required lockfile is a single variable in the script, so switching to a different package manager later is a one-line change.

Notes for your reviewers

There's no existing test harness for shell/linters/*.sh scripts, so I manually verified both checks against yarn-only, missing-yarn.lock, and each forbidden-lockfile scenario at both the root and api/clients/node, including a smoke test confirming the required-lockfile swap works as designed.

🤖 Generated with Claude Code

https://claude.ai/code/session_01NApzycVfBg7yxzWQEjU2G7

Adds shell/linters/nodejs-lockfile.sh, which fails when
package-lock.json, npm-shrinkwrap.json, pnpm-lock.yaml, bun.lock, or
bun.lockb are present, keeping yarn.lock as the only supported
lockfile for Node.js dependencies.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NApzycVfBg7yxzWQEjU2G7
api/clients/node/ is stencil's generated gRPC Node.js client, and its
CircleCI jobs run `yarn --frozen-lockfile`, which fails without a
committed yarn.lock. Extend shell/linters/nodejs-lockfile.sh to fail
when api/clients/node/package.json exists without a sibling yarn.lock.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NApzycVfBg7yxzWQEjU2G7
@getoutreach-ci-2

Copy link
Copy Markdown

Link to code coverage report (posted by coverbot 🤖)

yarn_lock_presence_linter only checked api/clients/node, missing the
common case of a root-level package.json (this repo included) with no
committed yarn.lock.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NApzycVfBg7yxzWQEjU2G7
Check for forbidden lockfiles only within nodejs_dirs (repo root and
api/clients/node) instead of scanning the whole repo tree, matching
the scope yarn_lock_presence_linter already uses.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NApzycVfBg7yxzWQEjU2G7
The header still described repo-wide lockfile enforcement after
lockfile_linter was scoped to nodejs_dirs. Refer to nodejs_dirs and
the forbidden_lockfiles concept by name instead of enumerating
directories or package managers, so the comment can't drift out of
sync with those arrays.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NApzycVfBg7yxzWQEjU2G7
Replace the hardcoded forbidden_lockfiles list and yarn-specific
presence check with all_lockfiles + required_lockfile: forbidden
lockfiles are derived by excluding required_lockfile from
all_lockfiles. Switching the required Node.js package manager (e.g.
yarn.lock to pnpm-lock.yaml) is now a one-line change.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NApzycVfBg7yxzWQEjU2G7
…dejs-lockfile-presence

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NApzycVfBg7yxzWQEjU2G7
@malept malept changed the title feat(lint): add linter to reject non-yarn Node.js lockfiles feat(lint): enforce yarn.lock as the only Node.js lockfile Sep 29, 2026
@malept
malept marked this pull request as ready for review September 29, 2026 03:02
@malept
malept requested a review from a team as a code owner September 29, 2026 03:02
@malept
malept merged commit b6b2a98 into main Sep 29, 2026
14 checks passed
@malept
malept deleted the malept-claude/relaxed-brown-xkfa7z branch September 29, 2026 18:57
@getoutreach-ci-2

Copy link
Copy Markdown

🎉 This PR is included in version 2.40.0-rc.4 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants