From 0b1bdca022bafe6274f8e1f994006baf00c15620 Mon Sep 17 00:00:00 2001 From: Matt Weiden <538456+mweiden@users.noreply.github.com> Date: Thu, 2 Jan 2020 10:21:14 -0800 Subject: [PATCH] Use `npm ci` instead of `npm install` during build (#1080) Currently the client build is not reproducible since, each time you run `make build-client` the package lockfile is updated. This should be handled separately by `make gen-package-lock` when developers actually want to update the dependencies. `npm ci` installs dependencies directly from the lockfile without updating them, making builds reproducible. --- Makefile | 4 ++-- client/Makefile | 4 ++++ 2 files changed, 6 insertions(+), 2 deletions(-) diff --git a/Makefile b/Makefile index e97af83a..4c34bbce 100644 --- a/Makefile +++ b/Makefile @@ -27,7 +27,7 @@ build: clean build-server .PHONY: build-client build-client: - cd client && $(MAKE) install build + cd client && $(MAKE) ci build .PHONY: build-server build-server: build-client @@ -122,7 +122,7 @@ release-directly-to-prod: dev-env pydist twine-prod .PHONY: dev-env dev-env: - cd client && $(MAKE) install + cd client && $(MAKE) ci pip install -r server/requirements-dev.txt .PHONY: gui-env diff --git a/client/Makefile b/client/Makefile index 47825cee..b682f8a7 100644 --- a/client/Makefile +++ b/client/Makefile @@ -2,6 +2,10 @@ clean: rm -rf node_modules +.PHONY: ci +ci: + npm ci client + .PHONY: install install: npm install client