Skip to content

fix: relax npm engine enforcement in reusable build - #30

Merged
vitormattos merged 2 commits into
mainfrom
fix/npm-build-engine-strict
Sep 20, 2026
Merged

vitormattos merged 2 commits into
mainfrom
fix/npm-build-engine-strict

Conversation

@vitormattos

Copy link
Copy Markdown
Member

Summary

Fix the real consumer regression found while validating npm-build in LibreCodeCoop/extract#154.

The reusable workflow selected Node ^22 from the project's own package.json, but enabling npm engine-strict caused npm ci to reject @nextcloud/axios@2.5.1, whose package metadata still declares Node ^20.

That is stricter than the previous workflow behavior and turns stale/transitive engine metadata into a build blocker.

Change

  • keep selecting Node from the project's declared engine;
  • keep using the npm bundled with that Node runtime;
  • keep avoiding installation of a PR-controlled npm range;
  • keep the pinned lockfile validation helper;
  • remove global engine-strict enforcement;
  • update the caller pin to immutable commit d96f4b5dcf780dea20d8843f54c4b52207dc25fd.

This preserves the supply-chain improvement without introducing a compatibility regression.

@vitormattos
vitormattos merged commit b69b189 into main Sep 20, 2026
4 of 5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant