build: use npm ci for clean, reproducible installs (#839)

Switch pr-build and the Docker image from `npm install` to `npm ci` (`npm ci --omit=dev` in the image), and enable setup-node's npm cache. Deterministic installs from the committed lockfile; CI now fails fast on an out-of-sync lockfile.

Depends on the lockfile being tracked (PR #838) — npm ci requires a committed package-lock.json.
This commit is contained in:
Jack Carter
2026-07-09 13:19:31 +02:00
committed by GitHub
parent e8c605047a
commit 51afd0cf71
2 changed files with 4 additions and 3 deletions

View File

@@ -22,9 +22,10 @@ jobs:
uses: actions/setup-node@v4
with:
node-version: '20'
cache: 'npm'
- name: Install dependencies
run: npm install
run: npm ci
- name: Lint MDX heading hierarchy
run: npm run lint:mdx

View File

@@ -10,8 +10,8 @@ RUN npm install --global pm2
# Utilise Docker cache to save re-installing dependencies if unchanged
COPY ./package*.json ./
# Install dependencies
RUN npm install --production
# Install dependencies (npm ci = clean, reproducible install from the lockfile)
RUN npm ci --omit=dev
# Copy all files
COPY ./ ./