feat(lint): enforce yarn.lock as the only Node.js lockfile - #1221
Merged
Merged
Conversation
Adds shell/linters/nodejs-lockfile.sh, which fails when package-lock.json, npm-shrinkwrap.json, pnpm-lock.yaml, bun.lock, or bun.lockb are present, keeping yarn.lock as the only supported lockfile for Node.js dependencies. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NApzycVfBg7yxzWQEjU2G7
api/clients/node/ is stencil's generated gRPC Node.js client, and its CircleCI jobs run `yarn --frozen-lockfile`, which fails without a committed yarn.lock. Extend shell/linters/nodejs-lockfile.sh to fail when api/clients/node/package.json exists without a sibling yarn.lock. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NApzycVfBg7yxzWQEjU2G7
|
Link to code coverage report (posted by coverbot 🤖) |
yarn_lock_presence_linter only checked api/clients/node, missing the common case of a root-level package.json (this repo included) with no committed yarn.lock. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NApzycVfBg7yxzWQEjU2G7
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NApzycVfBg7yxzWQEjU2G7
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NApzycVfBg7yxzWQEjU2G7
Check for forbidden lockfiles only within nodejs_dirs (repo root and api/clients/node) instead of scanning the whole repo tree, matching the scope yarn_lock_presence_linter already uses. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NApzycVfBg7yxzWQEjU2G7
The header still described repo-wide lockfile enforcement after lockfile_linter was scoped to nodejs_dirs. Refer to nodejs_dirs and the forbidden_lockfiles concept by name instead of enumerating directories or package managers, so the comment can't drift out of sync with those arrays. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NApzycVfBg7yxzWQEjU2G7
Replace the hardcoded forbidden_lockfiles list and yarn-specific presence check with all_lockfiles + required_lockfile: forbidden lockfiles are derived by excluding required_lockfile from all_lockfiles. Switching the required Node.js package manager (e.g. yarn.lock to pnpm-lock.yaml) is now a one-line change. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NApzycVfBg7yxzWQEjU2G7
…file Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NApzycVfBg7yxzWQEjU2G7
…dejs-lockfile-presence Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NApzycVfBg7yxzWQEjU2G7
malept
marked this pull request as ready for review
September 29, 2026 03:02
marnagy
approved these changes
Sep 29, 2026
|
🎉 This PR is included in version 2.40.0-rc.4 🎉 The release is available on: Your semantic-release bot 📦🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this PR does / why we need it
Node.js dependencies in Stenciled repos are standardized on Yarn. Adds
shell/linters/nodejs-lockfile.shto the built-in linter set, covering the repo root andapi/clients/node(stencil's generated gRPC Node.js client) — the only two locations where stencil manages a Node.jspackage.json:package-lock.json,npm-shrinkwrap.json,pnpm-lock.yaml,bun.lock, orbun.lockbis present in either directory.package.jsonwithout a committedyarn.lock.The required lockfile is a single variable in the script, so switching to a different package manager later is a one-line change.
Notes for your reviewers
There's no existing test harness for
shell/linters/*.shscripts, so I manually verified both checks against yarn-only, missing-yarn.lock, and each forbidden-lockfile scenario at both the root andapi/clients/node, including a smoke test confirming the required-lockfile swap works as designed.🤖 Generated with Claude Code
https://claude.ai/code/session_01NApzycVfBg7yxzWQEjU2G7