Repository navigation
npm install removes resolved and integrity properties from package-lock.json if installed from cache #4263
Description
Activity
- addedBugthing that needs fixingthing that needs fixingNeeds Triageneeds review for next stepsneeds review for next stepsRelease 8.xwork is associated with a specific npm 8 releasework is associated with a specific npm 8 release
on Jan 19, 2022 In my case, it removes the
resolvedentry for a company's remote repository, causing the CI pipeline to fail.npm 8.1.3node v16.3.0- Mac OS
Reacted by Josh and Kalman Keri@giovannipds what about with npm v8.5.2?
Reacted by G. Pires@ljharb thanks for interacting. In my case, the issue was in my repository config, it was misconfigured, that's why my
resolveds were being removed. Probably not related to what this ticket is about. What fixed for me:npm config set registry #YOUR_COMPANY_REGISTRY_URL
Reacted by Jordan Harband- added a commit that references this issue
on Apr 19, 2022 I managed to get proper
package-lock.json(withintegrityandresolvefields) after:- cleaning the npm cache
npm cache clean -f - removing
node_modulesin project folder - removing the
package-lock.jsonfile - running
npm installin now "clean" project folder
Reacted by Ibby Wedin, Michael Oberwasserlechner, Marcin Warpechowski, ETBlue, Hayden, Changdae Park, Evan Stoll, deluksic, Ekezoh, Jeroen Akkerman and 33 moreReacted by Ben Kraft, curvedriver, Rene Gonzalez, Laurens DC, Oleg Namaka, Miroslav Velk, Klaus Badelt, Dmitry Vakhnenko, Desu Sai Venkat, Jeffrey Holm and 5 moreReacted by Boris Shifrin, Xavier Lozinguez, Lazar Živković, Alex Hartford, Carlos Rivas, Mohammad Oujeil, Jose Alvarez and kassandraflanders-sbdReacted by Dominik Lesch, Rob, aarowman, Rene Gonzalez, Daniel Stockton and Robert Keyser- cleaning the npm cache
Just ran into this issue on
npm 8.19.2withnode v18.12.1.Cleared the cache and re-ran
npm install(slow), then it was okReacted by yu ganghyeon, Joey Carlisle and FedorI encountered the same issue with nodejs
16.19.1and npm8.19.3Reacted by Daksh Sagar, yu ganghyeon, julienzakaib and Fedorencountered the same issue with node
14.18.0and npm8.19.3Reacted by priyanshu-fportHappened on
npm v9.5.0too.vmaseks workaround worked.Reacted by Hayden, Zacchari Carde and deluksicWe also get this. Repeatedly. And it breaks our CI. Started after we updated to new versions of node and npm recently I think, but I see others get it on older versions as well. I'm not 100% if that is what cased it, as we have refactored a lot of stuff lately.
Current versions:
Node: 18.16.0
npm: 9.6.7
old versions:
Node: 16.5.1
npm: not sure unfortunately, but v8.x.x somethingOnly workaround is @vmasek workaround above. Would love to not have to delete
package-lock.jsonthe whole time, any idea whats causing this or if/when it will be fixed?Reacted by Vojtech MašekFor those who dislike the idea of unlocking and potentially version-bumping a ton of dependencies by deleting package-lock, here's a variant of the workaround above that seems to have worked for us:
- Delete
node_modulesfolder - Restore
package-lock.jsonfrom a recent commit prior to the undesired property removal (but keep the existingpackage.jsonversion) - Run
npm install
This should preserve the locked versions of any packages that were already installed prior to the corruption of package-lock, while ensuring anything newer based on
package.jsonalso gets installed/updated.Reacted by Joshua, Mika Vilpas, Rafael Pol, Jared Gollhardt, Kyle King, Laurens DC, heenee-bjak, Jaryk, Tomasz Domański, Laurie O and 4 more- Delete
I had this happened to me during npm solving merge conflicts with
npm-merge-driver. Similarly to @rbell-mfj, I restored package-lock.json before merge conflict resolution, applied the updates manually, integrity and resolved were kept.Reacted by Rohan Talip30 remaining items
- added a commit that references this issue
on Jun 18, 2026 - added a commit that references this issue
on Jun 28, 2026 I have opened PR #9688 that fixes this issue. The fix recovers resolved and integrity from the hidden lockfile when assertNoNewer rejects it, preserving the metadata across reinstall.
Reproduction: 69 resolved entries -> 1 after reinstall
After fix: 69 -> 69 preserved- added 8 commits that reference this issue
on Aug 9, 2026 - added a commit that references this issue
on Sep 15, 2026
Is there an existing issue for this?
This issue exists in the latest npm version
Current Behavior
If you run npm install with existing package cache inside "node_modules" it creates packages-lock.json without "resolved" and "integrity" properties.
Expected Behavior
"resolved" and "integrity" properties should stay remain after npm install using cache from "node_modules" folder
Steps To Reproduce
1.) Run npm install
2.) package-lock.json is created
3.) node modules are cached inside the project folder under "node_modules" folder
4.) delete package-lock.json and delete one package form "node_modules" folder
5.) Run npm install
6.) package-lock.json is created, but "resolved" and "integrity" properties are removed from each package descriptions inside package-lock.json
Environment
; copy and paste output from `npm config ls` here