Repository navigation
npm 12 - drops npm-shrinkwrap.json #1117
Description
Activity
I'm confused, what's the bug here? That a shrinkwrap file is ignored? That was an intentional change in v12. Rename the file to
package-lock.jsonand it should work fine.PR #1103 from @targos introduced
npm-shrinkwrap.jsonin Sep 2025.It's also mentioned in nodejs/node-core-utils#976 where
npm-shrinkwrap.jsonreplacespackage-lock.json.If there is to be a return to using
package-lock.jsongenerally, that may also need a general discussion. It impacts which versionsnpm install -g citgmactually installs, and so it would be a breaking change.I fixed the Prettier incompatibility in #1119
That only resolved that particular issue though.
ah, so the citgm package was intentionally shipping a shrinkwrap to lock consumer trees? that's the harmful behavior that npm 12 disallows by ignoring shrinkwrap.
I would suggest to rename
npm-shrinkwrap.jsontopackage-lock.jsonfor compatibility with npm 12 as also suggested by @ljharb.Downstream consumers of citgm are then free to update dependencies within the SemVer range defined in
package.json, which is particularly important for being able to resolve emerging vulnerabilities.This is however a breaking change and that should be accompanied by a major version bump for citgm.
PR #1129 proposes the rename of
npm-shrinkwrap.jsontopackage-lock.jsonfor compatible usage on supported npm versions, including npm 12.One approach could be, publish a patch that sets engines.npm to < 12, and then publish the major without the shrinkwrap file and without an engines.npm restriction.
One approach could be, publish a patch that sets engines.npm to < 12, and then publish the major without the shrinkwrap file and without an engines.npm restriction.
I don't think that would be necessary as far as usage in nodejs/node via Jenkins is concerned. citgm just gets installed as latest and any EBADENGINE warnings are ignored. If that weren't the case, it would already have failed trying to test against Node.js 26.
The npm 12 issues are in practice actually quite minor, but still deserve cleaning up. Hopefully the remaining PRs I've submitted can be reviewed and merged.
Closing this issue, as the steps to reproduce are no longer accurate.
#1188 fixes
npm testcompatibility with Node.js v27 nightly.I'll revisit after the release of Node.js 27 Alpha, planned for Oct 28, 2026.
Situation
npm 12 drops
npm-shrinkwrap.jsonused in this repo as a published lockfile. The npm 12.0.0 changelog states:npm installunder npm 12 installs dependencies according to theirSemVerrange specified inpackage.jsonand ignores the lower locked versions specified innpm-shrinkwrap.json.Example impact
If the repo is cloned and dependencies installed under npm 12, then
npm testfails.npm installignores the lockedprettier@3.6.2and installs insteadprettier@^3.6.2frompackage.jsonwhich causes prettier@3.9.6 to be installed, and written into the new lockfilepackage-lock.json.prettier@3.9.0 introduced formatting improvements which flagged a white space formatting issue in
lib/reporter/logger.jsthat was not previously flagged.Edit: A workaround for this example impact was implemented through PR #1119.
It can potentially impact other
dependencieswhere versions locked innpm-shrinkwrap.jsonare different from a fresh resolution based on^x.y.zSemVer ranges inpackage.json.Steps to reproduce
Ubuntu 24.04.4 LTS, Node.js 24.19.0, initially with npm 11.17.0
Logs
Suggestion
Review also how this impacts use of
citgmwhen installing usingnpm install -g citgmas specified in the README > Installation section.For the Prettier issue, that was used here more as an illustration of compatibility issues, update to latest and fix the formatting.