Skip to content

fix(ci): single bun.lock so frozen installs pass (CI red since #134) - #140

Merged
masonwyatt23 merged 1 commit into
mainfrom
fix/bun-lockfile-single-source
Sep 29, 2026
Merged

masonwyatt23 merged 1 commit into
mainfrom
fix/bun-lockfile-single-source

Conversation

@masonwyatt23

Copy link
Copy Markdown
Member

Problem: CI (verify) and the publish dry-run both run bun install --frozen-lockfile. The repo root had two lockfiles, bun.lock and package-lock.json, and Dependabot only updated package-lock.json:

bun.lock fell out of sync, so every PR has failed at Install dependencies. Dependabot auto-merge kept merging anyway, because main has no required checks.

Fix:

  • Regenerated bun.lock from the current package-lock.json using bun's lockfile migration, so resolved versions match what Dependabot chose (for example ip-address 10.7.2; the old bun.lock had 10.1.0).
  • Removed the stale root package-lock.json. Dependabot's npm ecosystem now maintains bun.lock directly. video/package-lock.json is unchanged.
  • publish.yml cache key hashed bun.lockb, which does not exist. It now uses bun.lock.

Local results (bun 1.4.2): bun install --frozen-lockfile OK; lint 0 errors; typecheck OK; build OK; MORPHKIT_NO_AI=1 bun test: 257 pass, 7 skip, 0 fail. The skips are the macOS-only swift compile tests.

Open Dependabot PRs will need a rebase once this merges. Dependabot does that on its own.

CI and the publish dry-run run `bun install --frozen-lockfile`, but the root
had both bun.lock and package-lock.json. Dependabot only updated
package-lock.json (#134 bumped @anthropic-ai/sdk to ^0.128.0 in package.json,
#139 bumped ip-address), so bun.lock drifted and every CI run since has failed
at 'Install dependencies' while Dependabot auto-merge kept merging.

- Regenerate bun.lock from the current package-lock.json resolution (bun's
  lockfile migration), so installed versions match what Dependabot resolved
  (e.g. ip-address 10.7.2, previously 10.1.0 in bun.lock).
- Remove the stale package-lock.json so Dependabot updates bun.lock from now on.
- publish.yml cache key hashed bun.lockb, which does not exist; use bun.lock.
@vercel

vercel Bot commented Sep 29, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
morphkit-landing Ready Ready Preview Sep 29, 2026 2:20pm UTC

Request Review

@masonwyatt23
masonwyatt23 merged commit 851f14e into main Sep 29, 2026
6 checks passed
@masonwyatt23
masonwyatt23 deleted the fix/bun-lockfile-single-source branch September 29, 2026 14:28

This branch was successfully deployed

1 active deployment
Preview — 101bef7e Deployed Sep 29, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant