The deploy died on `npm ci` with "Missing: @emnapi/core@1.11.3 from lock file". Nothing was wrong with the code — the lock really was incomplete, and the Dockerfile was right to refuse it. I broke it. Adding leaflet ran `npm install` under npm 11.6.2; the builder is node:22-alpine, which ships npm 10.9.8. npm 11 prunes optional platform packages that npm 10 still validates, and it dropped `@emnapi/core` and `@emnapi/runtime` — transitive optional deps of `@tailwindcss/oxide-wasm32-wasi`. Both were present in the lock atb760c1aand absent from34bf798onward. Regenerated with `npx npm@10.9.8 install --package-lock-only`, which restores both entries and keeps leaflet 1.9.4 / @types/leaflet 1.9.22. Verified by running the builder's exact command in a scratch directory: the old lock reproduces the failure, the new one gives "added 212 packages" under npm 10.9.8 AND under npm 11.6.2 — so it holds whichever npm the image ships. No Dockerfile change was needed for that. The Dockerfile comment did need one. It said the fix was "`npm install` locally and COMMIT the updated package-lock.json", which is exactly the step that caused this. It now says to prove the lock against npm 10.9.8 in a scratch directory before pushing, and how to regenerate it if it fails. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JYEsb8PNZ19G9R8gUjTU7n
153 KiB
153 KiB