Repository navigation
Eliminate npm lockfiles estate-wide (npm-avoidant) #67
Description
Activity
- addedmajorMajor / load-bearing workMajor / load-bearing workrequirements-targetTracked requirements-target item (joint-close)Tracked requirements-target item (joint-close)
on May 16, 2026 - added a parent issue
on May 16, 2026 Template-side already satisfied:
rsr-template-repo/.gitignoreandv3-templater/.gitignoreboth carrypackage-lock.jsonand**/package-lock.json. Remaining work is estate-wide propagation + gitbot reject-on-reintroduction (epic-ongoing). Refs #66.Progress 2026-05-19 (keeping OPEN):
- Template
.gitignore✓ (rsr-template-repo#49, v3-templater#69 — 2026-05-16) - Enforcement ✓ — standards#148 merged:
governance-reusable.ymlnow fails on trackedpackage-lock.json(recursivegit ls-files) +bun.lockb/yarn.lock/.npmrc; gitbot-fleet#170 addsfix-tracked-package-lock.shrecipe. - Audit (2026-05-19 read-only sweep): 10 repos still track
package-lock.json:ci,claude-integrations,developer-ecosystem,git-scripts,hyperpolymath-archive,panll,repos-monorepo,rescript-tea,typed-wasm,v3-templater(last one fixed by template PR).
Remaining for close: consumer propagation to reach 0 tracked. Use
standards/scripts/propagate-gitignore-67-68.sh --fix(ships in #148) per repo; each becomes a reviewable branch — no unattended estate-wide mutation.- Template
- added 5 commits that reference this issue
on May 20, 2026 Cross-link update (2026-05-31): the no-lockfiles rule is now functionally subsumed by the npm→Deno campaign tracked at standards#253 (UMBRELLA) + STEPs #261, #262, #265, #268, #270, #273, #275. When a repo's npm→Deno migration lands, its
package-lock.jsonnecessarily goes away (Deno has no node_modules/lockfile concept).Recommend closing this issue once standards#253 reaches convergence — or close now as superseded if you'd rather track "no-lockfile" only via the broader migration's per-step PRs. Leaving open for owner decision.
Closing — superseded by standards#253 (npm → Deno estate migration UMBRELLA) + its 7 STEP issues. The no-tracked-package-lock.json rule is implicit in the Deno migration: every repo that completes its #253 STEP loses its
package-lock.jsonas a side-effect.Per-repo migration PRs are landing throughout 2026-05-30/31 (current count: dozens in flight across affinescript, ambientops, avow-protocol, blocky-writer, civic-connect, claude-integrations, coq-jr, echidna, flatracoon, laniakea, no-nonsense-nntps, odds-and-sods-package-manager, polyglot-i18n, reposystem, rescript-ecosystem, no-nonsense-nntps, session-sentinel, …).
If a separate "audit lockfile residue post-#253" issue is desired at convergence, file fresh.
Scope: no tracked package-lock.json anywhere in the estate; npm-avoidant codified.
Mechanism: add package-lock.json to canonical .gitignore in rsr-template-repo + v3-templater, propagate to consumers, gitbot rejects re-introduction. docs/JS-RUNTIME-POLICY.adoc references purge-node-modules.sh.
Acceptance: 0 tracked package-lock.json estate-wide; template .gitignore covers it; enforcement wired.
Parent: #66