From 9cafea0eed6ef570e8af585be5bc353aca0d6eaf Mon Sep 17 00:00:00 2001 From: jekkos Date: Tue, 29 Sep 2026 13:16:18 +0200 Subject: [PATCH] fix(release): keep package-lock.json version in sync on bump (#4718) * fix(release): keep package-lock.json version in sync on bump The release bump step updated app/Config/App.php and package.json but left package-lock.json on the old version, so the lockfile drifted out of sync with package.json on every release. Bump the @opensourcepos/ opensourcepos package version in package-lock.json (top-level and packages."") using the same scoped approach, and stage it in the bump commit. Fixes #4717 * fix(release): sync package-lock.json to 3.4.3 on master Bump the @opensourcepos/opensourcepos version in package-lock.json (top-level + packages."") from 3.4.2 to 3.4.3 to match package.json, which was already bumped during the 3.4.3 dev bump. This repairs the current drift introduced by the bump commit so the upcoming 3.4.3 release ships with package.json and package-lock.json in sync. Part of #4717 --- .github/workflows/release.yml | 10 +++++++++- package-lock.json | 4 ++-- 2 files changed, 11 insertions(+), 3 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 939dca9a8..c9f306ce8 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -138,6 +138,13 @@ jobs: sed -i "s/public string \\\$application_version = '[^']*';/public string \\\$application_version = '$NEXT';/" app/Config/App.php sed -i "s/\"version\": \"[^\"]*\",/\"version\": \"$NEXT\",/" package.json + # Keep package-lock.json in sync: bump only the @opensourcepos/opensourcepos + # package version (top-level + packages.""), leave dependency versions alone. + awk -v v="$NEXT" ' + /"name": "@opensourcepos\/opensourcepos"/ { expect=1 } + expect && /"version": / { sub(/"version": "[^"]*"/, "\"version\": \"" v "\""); expect=0 } + { print } + ' package-lock.json > .package-lock.tmp && mv .package-lock.tmp package-lock.json # Update the "latest X.Y version" README line only when major.minor changes NEW_MM=$(echo "$NEXT" | cut -d. -f1,2) OLD_MM=$(echo "$CURRENT" | cut -d. -f1,2) @@ -148,10 +155,11 @@ jobs: echo "=== version refs after bump ===" grep "application_version" app/Config/App.php grep '"version"' package.json | head -1 + grep -A1 '"name": "@opensourcepos/opensourcepos"' package-lock.json git config user.name "github-actions[bot]" git config user.email "github-actions[bot]@users.noreply.github.com" - git add app/Config/App.php package.json + git add app/Config/App.php package.json package-lock.json [ "$NEW_MM" != "$OLD_MM" ] && git add README.md git commit -m "chore: bump version to $NEXT" git push origin HEAD diff --git a/package-lock.json b/package-lock.json index 5ef9efa33..13a032102 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "@opensourcepos/opensourcepos", - "version": "3.4.2", + "version": "3.4.3", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "@opensourcepos/opensourcepos", - "version": "3.4.2", + "version": "3.4.3", "license": "MIT", "dependencies": { "bootstrap": "^3.4.1",