23

I'm looking for an equivalent for yarn's --pure-lockfile flag.

This flag is useful when installing dependencies in CI, when you want it to read your lockfile but not modify it.

Does npm v5 have an equivalent?

Yves M.
  • 28,433
  • 22
  • 100
  • 135
callum
  • 30,419
  • 32
  • 99
  • 150

2 Answers2

27

npm 5.7 introduced the npm ci subcommand:

the main differences between using npm install and npm ci are:

  • The project must have an existing package-lock.json or npm-shrinkwrap.json.
  • If dependencies in the package lock do not match those in package.json, npm ci will exit with an error, instead of updating the package lock.
  • npm ci can only install entire projects at a time: individual dependencies cannot be added with this command.
  • If a node_modules is already present, it will be automatically removed before npm ci begins its install.
  • It will never write to package.json or any of the package-locks: installs are essentially frozen.
Community
  • 1
  • 1
Tamlyn
  • 20,422
  • 11
  • 104
  • 124
-3

this is how I did in my dockerfile

RUN npm install --pure-lockfile

it should work perfect.

  • 1
    I've looked and found no documentation for anything called `--pure-lockfile` in npm. I believe this flag is ignored. – Nateowami Oct 18 '19 at 22:04