janus-idp / backstage-showcase

Enterprise-ready Backstage distribution

Home Page:https://showcase.janus-idp.io

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Fail the build if the yarn.lock file is changed after running yarn install

gashcrumb opened this issue · comments

What do you want to improve?

Often when running yarn install after updating the yarn.lock file contains changes.

What is the current behavior?

This is not ideal as it means there's inconsistencies between what folks are committing and what is being tested in github actions.

What will the new behavior be?

The build action will fail if there's changes to the yarn.lock file after running yarn install

See this comment for more information:

Yes this is a copy of janus-idp/backstage-plugins#1169

See https://issues.redhat.com//browse/RHIDP-1204 for updates.

PRs for this:

PR is failing already with

After 'yarn install', workspace is dirty! The following files have changed:

app-config.example.yaml
app-config.yaml
yarn.lock

-- https://github.com/janus-idp/backstage-showcase/actions/runs/8646895996/job/23707183425?pr=1174

and

After 'yarn install', workspace is dirty! The following files have changed:

app-config.example.yaml
app-config.yaml

-- https://github.com/janus-idp/backstage-showcase/actions/runs/8646912247/job/23707235821?pr=1175

Should we exclude app-config.* from the list of files that can be dirty during a release?

I think not to be honest. For me it's a red flag that there's something going on that needs to be investigated. Or it indicates that an upgrade has migrated the configuration files, in which case I think that this kind of change to the files should be required to be included in a PR update as well.

so you're saying this is a GOOD and EXPECTED failure, and the change proposed by this PR is approved?

yep 😄

I take that back after looking at the PR action 😄 . Turns out the PR check build is copying the app config into place for some reason, so we should leave those two changed files as-is for now and just focus on the yarn.lock file.

Woo! Snyk PRs are now failing with

After 'yarn install', workspace is dirty! The following files have changed:

app-config.example.yaml
app-config.yaml
yarn.lock

https://github.com/janus-idp/backstage-showcase/actions/runs/8661941105/job/23752905502?pr=1104

So... I'm going to resolve this.