Skip to content

Eliminate npm lockfiles estate-wide (npm-avoidant) #67

Description

@hyperpolymath

Scope: no tracked package-lock.json anywhere in the estate; npm-avoidant codified.

Mechanism: add package-lock.json to canonical .gitignore in rsr-template-repo + v3-templater, propagate to consumers, gitbot rejects re-introduction. docs/JS-RUNTIME-POLICY.adoc references purge-node-modules.sh.

Acceptance: 0 tracked package-lock.json estate-wide; template .gitignore covers it; enforcement wired.

Parent: #66

Activity

  1. hyperpolymath commented on May 16, 2026

    @hyperpolymath
    OwnerAuthor

    Template-side already satisfied: rsr-template-repo/.gitignore and v3-templater/.gitignore both carry package-lock.json and **/package-lock.json. Remaining work is estate-wide propagation + gitbot reject-on-reintroduction (epic-ongoing). Refs #66.

  2. hyperpolymath commented on May 19, 2026

    @hyperpolymath
    OwnerAuthor

    Progress 2026-05-19 (keeping OPEN):

    • Template .gitignore ✓ (rsr-template-repo#49, v3-templater#69 — 2026-05-16)
    • Enforcement ✓ — standards#148 merged: governance-reusable.yml now fails on tracked package-lock.json (recursive git ls-files) + bun.lockb/yarn.lock/.npmrc; gitbot-fleet#170 adds fix-tracked-package-lock.sh recipe.
    • Audit (2026-05-19 read-only sweep): 10 repos still track package-lock.json: ci, claude-integrations, developer-ecosystem, git-scripts, hyperpolymath-archive, panll, repos-monorepo, rescript-tea, typed-wasm, v3-templater (last one fixed by template PR).

    Remaining for close: consumer propagation to reach 0 tracked. Use standards/scripts/propagate-gitignore-67-68.sh --fix (ships in #148) per repo; each becomes a reviewable branch — no unattended estate-wide mutation.

  3. hyperpolymath commented on May 30, 2026

    @hyperpolymath
    OwnerAuthor

    Cross-link update (2026-05-31): the no-lockfiles rule is now functionally subsumed by the npm→Deno campaign tracked at standards#253 (UMBRELLA) + STEPs #261, #262, #265, #268, #270, #273, #275. When a repo's npm→Deno migration lands, its package-lock.json necessarily goes away (Deno has no node_modules/lockfile concept).

    Recommend closing this issue once standards#253 reaches convergence — or close now as superseded if you'd rather track "no-lockfile" only via the broader migration's per-step PRs. Leaving open for owner decision.

  4. hyperpolymath commented on May 30, 2026

    @hyperpolymath
    OwnerAuthor

    Closing — superseded by standards#253 (npm → Deno estate migration UMBRELLA) + its 7 STEP issues. The no-tracked-package-lock.json rule is implicit in the Deno migration: every repo that completes its #253 STEP loses its package-lock.json as a side-effect.

    Per-repo migration PRs are landing throughout 2026-05-30/31 (current count: dozens in flight across affinescript, ambientops, avow-protocol, blocky-writer, civic-connect, claude-integrations, coq-jr, echidna, flatracoon, laniakea, no-nonsense-nntps, odds-and-sods-package-manager, polyglot-i18n, reposystem, rescript-ecosystem, no-nonsense-nntps, session-sentinel, …).

    If a separate "audit lockfile residue post-#253" issue is desired at convergence, file fresh.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    majorMajor / load-bearing workrequirements-targetTracked requirements-target item (joint-close)

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions