Skip to content

[BUG] npm update can write a lockfile that npm install rejects #9604

Description

@dale-lakes

Is there an existing issue for this?

  • I have searched the existing issues

This issue exists in the latest npm version

  • I am using the latest npm

Current Behavior

npm update can successfully write a package-lock.json that a subsequent plain npm install immediately rejects with ERESOLVE.

The concrete repro uses Storybook and Vite+:

  • valid starting lockfile: storybook@10.3.5, @storybook/react-vite@10.3.5, vite-plus@0.2.0
  • storybook@10.3.5 has no vite-plus peer dependency; its only peer dependency is optional prettier
  • npm update exits 0 and updates the lockfile to storybook@10.4.6, @storybook/react-vite@10.4.6, vite-plus@0.2.1
  • storybook@10.4.6 has optional peer vite-plus@^0.1.15
  • semver ^0.1.15 does not include any 0.2.x release, so neither vite-plus@0.2.0 nor vite-plus@0.2.1 can satisfy it
  • the next npm install fails with ERESOLVE

So npm starts from a valid/installable lockfile, npm update reports success, but npm's own install command cannot reproduce the updated lockfile.

Expected Behavior

npm update should not leave the project with a lockfile that npm install immediately rejects.

Reasonable outcomes would be either:

  • npm update avoids selecting updates that create an install-invalid peer graph, or
  • npm update fails non-zero and does not leave the lockfile in the invalid updated state.

Steps To Reproduce

This uses npx --yes npm@11.17.0 ... only to force the latest npm version even on machines with an older npm on PATH. The initial install intentionally pins exact versions while saving caret ranges, creating a valid starting lockfile that a later update corrupts.

rm -rf /tmp/npm-update-install-eresolve-repro
mkdir -p /tmp/npm-update-install-eresolve-repro
cd /tmp/npm-update-install-eresolve-repro

npx --yes npm@11.17.0 init -y
npx --yes npm@11.17.0 install --save-dev --save-prefix='^' \
  storybook@10.3.5 \
  @storybook/react-vite@10.3.5 \
  vite-plus@0.2.0 \
  react@18.3.1 \
  react-dom@18.3.1

node - <<'NODE'
const p = require('./package-lock.json').packages
console.log('initial lock:', {
  storybook: p['node_modules/storybook'].version,
  storybookPeers: p['node_modules/storybook'].peerDependencies,
  storybookPeerMeta: p['node_modules/storybook'].peerDependenciesMeta,
  reactVite: p['node_modules/@storybook/react-vite'].version,
  vitePlus: p['node_modules/vite-plus'].version,
})
NODE

echo '--- npm update ---'
npx --yes npm@11.17.0 update

echo '--- lockfile after update ---'
node - <<'NODE'
const p = require('./package-lock.json').packages
console.log('after update lock:', {
  storybook: p['node_modules/storybook'].version,
  storybookPeers: p['node_modules/storybook'].peerDependencies,
  storybookPeerMeta: p['node_modules/storybook'].peerDependenciesMeta,
  reactVite: p['node_modules/@storybook/react-vite'].version,
  vitePlus: p['node_modules/vite-plus'].version,
})
NODE

echo '--- npm install after update ---'
npx --yes npm@11.17.0 install

Observed output from the important parts:

initial lock: {
  storybook: '10.3.5',
  storybookPeers: { prettier: '^2 || ^3' },
  storybookPeerMeta: { prettier: { optional: true } },
  reactVite: '10.3.5',
  vitePlus: '0.2.0'
}

added 5 packages, changed 12 packages, and audited 227 packages in 3s

after update lock: {
  storybook: '10.4.6',
  storybookPeers: {
    '@types/react': '^16.8.0 || ^17.0.0 || ^18.0.0 || ^19.0.0',
    prettier: '^2 || ^3',
    'vite-plus': '^0.1.15'
  },
  storybookPeerMeta: {
    '@types/react': { optional: true },
    prettier: { optional: true },
    'vite-plus': { optional: true }
  },
  reactVite: '10.4.6',
  vitePlus: '0.2.1'
}

npm error code ERESOLVE
npm error ERESOLVE could not resolve
npm error
npm error While resolving: storybook@10.4.6
npm error Found: vite-plus@0.2.1
npm error node_modules/vite-plus
npm error   dev vite-plus@"^0.2.0" from the root project
npm error
npm error Could not resolve dependency:
npm error peerOptional vite-plus@"^0.1.15" from storybook@10.4.6

Environment

npm = 11.17.0
node = v24.17.0
os = macOS arm64
package manager = npm / package-lock.json

Activity

  1. added a commit that references this issue on Jun 24, 2026
    2aa1c7c
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions