Skip to content

npm install removes resolved and integrity properties from package-lock.json if installed from cache #4263

Description

@SymbioticKilla

Is there an existing issue for this?

  • I have searched the existing issues

This issue exists in the latest npm version

  • I am using the latest npm

Current Behavior

If you run npm install with existing package cache inside "node_modules" it creates packages-lock.json without "resolved" and "integrity" properties.

Expected Behavior

"resolved" and "integrity" properties should stay remain after npm install using cache from "node_modules" folder

Steps To Reproduce

1.) Run npm install
2.) package-lock.json is created
3.) node modules are cached inside the project folder under "node_modules" folder
4.) delete package-lock.json and delete one package form "node_modules" folder
5.) Run npm install
6.) package-lock.json is created, but "resolved" and "integrity" properties are removed from each package descriptions inside package-lock.json

Environment

  • npm: 8.1.2
  • Node.js: 16.3.2
  • OS Name: Windows 10
  • System Model Name:
  • npm config:
; copy and paste output from `npm config ls` here

Activity

  1. added
    Bugthing that needs fixing
    Needs Triageneeds review for next steps
    Release 8.xwork is associated with a specific npm 8 release
    on Jan 19, 2022
  2. giovannipds commented on Feb 24, 2022

    @giovannipds

    In my case, it removes the resolved entry for a company's remote repository, causing the CI pipeline to fail.

    • npm 8.1.3
    • node v16.3.0
    • Mac OS
  3. ljharb commented on Feb 25, 2022

    @ljharb
    Contributor

    @giovannipds what about with npm v8.5.2?

  4. giovannipds commented on Feb 25, 2022

    @giovannipds

    @ljharb thanks for interacting. In my case, the issue was in my repository config, it was misconfigured, that's why my resolveds were being removed. Probably not related to what this ticket is about. What fixed for me:

    npm config set registry #YOUR_COMPANY_REGISTRY_URL
  5. added a commit that references this issue on Apr 19, 2022
  6. vmasek commented on Jul 3, 2022

    @vmasek

    I managed to get proper package-lock.json (with integrity and resolve fields) after:

    • cleaning the npm cache npm cache clean -f
    • removing node_modules in project folder
    • removing the package-lock.json file
    • running npm install in now "clean" project folder
  7. aarowman commented on Jan 25, 2023

    @aarowman

    Just ran into this issue on npm 8.19.2 with node v18.12.1.

    Cleared the cache and re-ran npm install (slow), then it was ok

  8. cdpark0530 commented on Mar 19, 2023

    @cdpark0530

    I encountered the same issue with nodejs 16.19.1 and npm 8.19.3

  9. daksh-sagar commented on Apr 14, 2023

    @daksh-sagar

    encountered the same issue with node 14.18.0 and npm 8.19.3

  10. sorgloomer commented on Apr 26, 2023

    @sorgloomer

    Happened on npm v9.5.0 too. vmaseks workaround worked.

  11. kfayelun commented on Jul 5, 2023

    @kfayelun

    We also get this. Repeatedly. And it breaks our CI. Started after we updated to new versions of node and npm recently I think, but I see others get it on older versions as well. I'm not 100% if that is what cased it, as we have refactored a lot of stuff lately.
    Current versions:
    Node: 18.16.0
    npm: 9.6.7
    old versions:
    Node: 16.5.1
    npm: not sure unfortunately, but v8.x.x something

    Only workaround is @vmasek workaround above. Would love to not have to delete package-lock.json the whole time, any idea whats causing this or if/when it will be fixed?

  12. rbell-mfj commented on Aug 10, 2023

    @rbell-mfj

    For those who dislike the idea of unlocking and potentially version-bumping a ton of dependencies by deleting package-lock, here's a variant of the workaround above that seems to have worked for us:

    1. Delete node_modules folder
    2. Restore package-lock.json from a recent commit prior to the undesired property removal (but keep the existing package.json version)
    3. Run npm install

    This should preserve the locked versions of any packages that were already installed prior to the corruption of package-lock, while ensuring anything newer based on package.json also gets installed/updated.

  13. Rapol commented on Sep 7, 2023

    @Rapol

    I had this happened to me during npm solving merge conflicts with npm-merge-driver. Similarly to @rbell-mfj, I restored package-lock.json before merge conflict resolution, applied the updates manually, integrity and resolved were kept.

  14. 30 remaining items

  15. added a commit that references this issue on Jun 28, 2026
    def70d7
  16. Amilliox commented on Jun 28, 2026

    @Amilliox

    I have opened PR #9688 that fixes this issue. The fix recovers resolved and integrity from the hidden lockfile when assertNoNewer rejects it, preserving the metadata across reinstall.

    Reproduction: 69 resolved entries -> 1 after reinstall
    After fix: 69 -> 69 preserved

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Bugthing that needs fixingNeeds Triageneeds review for next stepsPriority 1high priority issueRelease 8.xwork is associated with a specific npm 8 release

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions