Skip to content

script-utils/package-lock-integrity

Refuses a package-lock.json whose installed entries have lost their resolved or integrity field.

You get such a lock by deleting package-lock.json while node_modules is still installed and then running npm install. npm records every package it reuses from node_modules with its version only. One measured lock went from 7 such entries to 1064 of 1234 in a single regeneration. npm never fills the two fields back in afterwards: a clean install into an empty directory does not, and neither does npm install --package-lock-only. npm ci skips integrity verification for those packages, so the defect is permanent and every other check stays green.

The check reads the JSON and nothing else. It makes no network call and finishes in well under a second, which is why gate() runs it before anything else.

Function Description
assertPackageLockIntegrity Throws when the project’s package-lock.json has an installed entry without resolved or integrity. A project with no package-lock.json, such as one on another package manager, passes.
findPackageLockEntriesMissingIntegrity Finds the packages entries of a lockfile that have no resolved field, or that have a registry resolved field and no integrity field. Some entries never have these fields in a healthy lock, so they are skipped: the root (''), a link, a workspace source folder (its key has no node_modules/ segment), and a bundled dependency (inBundle), which comes inside its parent’s tarball. integrity is only required when resolved is a registry URL, because npm records no integrity for a git dependency.