fix: copy lockfile into Docker builder stage and use npm ci#218
Merged
jakebromberg merged 1 commit intomainfrom Mar 2, 2026
Merged
fix: copy lockfile into Docker builder stage and use npm ci#218jakebromberg merged 1 commit intomainfrom
jakebromberg merged 1 commit intomainfrom
Conversation
The builder stages in both Dockerfiles copied only package.json, causing npm install to resolve caret ranges to the latest compatible versions rather than using the locked versions. This pulled better-auth 1.5.1 (which has breaking type changes) instead of the locked 1.4.9, failing every PR's integration tests. Copy package-lock.json alongside package.json and switch to npm ci for deterministic, reproducible builds.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Dockerfile.backendandDockerfile.authonly copiedpackage.json, notpackage-lock.jsonnpm installto resolve caret ranges to latest compatible versions instead of locked versionsbetter-authresolved to 1.5.1 (which has breaking type changes inAuth) instead of the locked 1.4.9, failing integration tests on every open PRpackage-lock.jsoninto the builder stage and switch fromnpm installtonpm cifor deterministic buildsTest plan