Repository navigation
fix(ci): single bun.lock so frozen installs pass (CI red since #134) - #140
Merged
Merged
Conversation
CI and the publish dry-run run `bun install --frozen-lockfile`, but the root had both bun.lock and package-lock.json. Dependabot only updated package-lock.json (#134 bumped @anthropic-ai/sdk to ^0.128.0 in package.json, #139 bumped ip-address), so bun.lock drifted and every CI run since has failed at 'Install dependencies' while Dependabot auto-merge kept merging. - Regenerate bun.lock from the current package-lock.json resolution (bun's lockfile migration), so installed versions match what Dependabot resolved (e.g. ip-address 10.7.2, previously 10.1.0 in bun.lock). - Remove the stale package-lock.json so Dependabot updates bun.lock from now on. - publish.yml cache key hashed bun.lockb, which does not exist; use bun.lock.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem: CI (
verify) and the publish dry-run both runbun install --frozen-lockfile. The repo root had two lockfiles,bun.lockandpackage-lock.json, and Dependabot only updatedpackage-lock.json:@anthropic-ai/sdkto^0.128.0in package.json.ip-address.bun.lockfell out of sync, so every PR has failed at Install dependencies. Dependabot auto-merge kept merging anyway, because main has no required checks.Fix:
bun.lockfrom the currentpackage-lock.jsonusing bun's lockfile migration, so resolved versions match what Dependabot chose (for example ip-address 10.7.2; the old bun.lock had 10.1.0).package-lock.json. Dependabot's npm ecosystem now maintainsbun.lockdirectly.video/package-lock.jsonis unchanged.publish.ymlcache key hashedbun.lockb, which does not exist. It now usesbun.lock.Local results (bun 1.4.2):
bun install --frozen-lockfileOK; lint 0 errors; typecheck OK; build OK;MORPHKIT_NO_AI=1 bun test: 257 pass, 7 skip, 0 fail. The skips are the macOS-only swift compile tests.Open Dependabot PRs will need a rebase once this merges. Dependabot does that on its own.