`npm` version isn't pinned using `corepack`, so the `package-lock.json` may differ for contributors
envgap__faisalman__ua-parser-js-831
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
3d80848d35886d497c6f8e34219c9428b4f982a3- Manifest
package.json- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
faisalman/ua-parser-js #831 · read the original issue
Currently, the `package-lock.json` is generated with the `npm` version before the `11.14.0`, where the peer resolution was improved. Therefore, when I execute the `npm i` on my machine, I'm getting a diff for the lockfile: <img height="50" src="https://github.com/user-attachments/assets/333f7340-8af9-45d6-bc54-c137b2dcfde0" /> That's slightly annoying and may cause contributors to submit "conflicting" versions of the `package-lock.json`. **Describe the solution you'd like** A clear way to avoid those conflicts is using the `corepack`'s package manager pinning. That way, all the contributors will use the same `npm` version, w/o overriding `package-lock.json` needlesly.
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]