Skip to content

build(e2e): commit package-lock.json for the Playwright suite - #9199

Open
DoDiODev wants to merge 1 commit into
apache:mainfrom
DoDiODev:pr/wave12-e2e-lockfile
Open

DoDiODev wants to merge 1 commit into
apache:mainfrom
DoDiODev:pr/wave12-e2e-lockfile

Conversation

@DoDiODev

@DoDiODev DoDiODev commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Summary

e2e/ has been a Dependabot npm directory since #9089, but it only contains a package.json with a caret range and no lockfile. Every install therefore resolves whatever Playwright release is current, and Dependabot has to guess the version it is updating from — #9098 was titled "bump @playwright/test from 1.63.0 to 1.62.1" although it actually raised the range from ^1.58.2 to ^1.62.1.

This PR commits a lockfile and updates the related Dependabot comment.

Changes

File Change
e2e/package-lock.json New, lockfileVersion 3, public npm registry. Resolves @playwright/test ^1.63.0 to 1.63.0 (plus playwright, playwright-core)
.github/dependabot.yml The /e2e comment no longer says "this directory has no lockfile". versioning-strategy: increase stays so the declared range and the locked version move together

Why npm: e2e/package.json is the npm init scaffold and declares no packageManager; npm ci works with any Node installation. **/*.json is already excluded in .licenserc.yaml, so no license-config change is needed.

No change to package.json, test code or any workflow.

Verification

Check Result
npm ci from the committed lockfile ✅ 3 packages, playwright --version → 1.63.0
resolved URLs ✅ all https://registry.npmjs.org/
skywalking-eyes header check ✅
Unmodified upstream workflows in the fork on top of current main ✅ all 8 green, incl. e2e-mysql and e2e-postgres

`e2e/` has been a Dependabot `npm` directory since apache#9089 but ships only a
`package.json` with a caret range. Without a lockfile every install
resolves whatever Playwright release is current, and Dependabot has to
guess the "from" version (apache#9098 was titled "1.63.0 -> 1.62.1" while it
actually raised the range from ^1.58.2).

- Add `e2e/package-lock.json` (lockfileVersion 3, public npm registry),
  resolving `@playwright/test` ^1.63.0 to 1.63.0. `package.json` is the
  npm-init scaffold and declares no `packageManager`, so npm is the
  natural tool; `**/*.json` is already excluded in `.licenserc.yaml`.
- Update the `/e2e` comment in `.github/dependabot.yml`: the directory
  now has a lockfile. `versioning-strategy: increase` stays, so the
  declared range and the locked version move together.

Signed-off-by: DoDiODev <DoDiDev@proton.me>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant