Angular 22 requires Node ^22.22.3 || ^24.15.0 || >=26.0.0, and package.json
said nothing about it. On a machine half a patch below that floor — 22.22.2,
which is what this development container has on PATH — every `ng` command
refuses to start, so `npm test` and `npm run build` fail with a version
error rather than a test failure. Nothing in the repository pointed at the
cause; you had to already know.
The range is Angular's, taken verbatim rather than guessed at, because it is
the binding constraint. Every other direct dependency is looser and fully
contained by it: vitest wants ^20 || ^22 || >=24, jsdom ^20.19 || ^22.12 ||
>=24, tsx >=18, typescript >=14.17, Playwright >=20.
This moves the complaint earlier and makes it name the project. `npm ci` now
prints EBADENGINE for star-map itself before anything is installed, instead
of the first Angular command failing several steps later. It stays a warning
rather than an error — turning it into one needs engine-strict in .npmrc,
which would hard-fail installs on any unlisted version, and that is a
stricter policy than this change is claiming to make.
The lockfile carries the field too: npm mirrors the root package's engines
into it, and a lockfile that disagrees with package.json is one npm has to
resolve rather than trust. Regenerated with --package-lock-only, which
changed those three lines and no dependency.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WaySiNst4HhDXBHnMy8p5G
Nothing has ever checked this project automatically. There are no workflows,
so the pull request's green tick means only that the checks were run by hand
on one machine, and nothing would catch a regression pushed later.
The lockfile had to come first. `npm ci` is the only install that guarantees
CI tests the dependency tree that is actually committed, and it refuses to
run without package-lock.json — which was gitignored. Un-ignoring it also
pins the 617 packages this was built and verified against; without it, a
transitive release could change what CI runs from one day to the next with
no commit to point at. Checked before committing: every entry resolves to
registry.npmjs.org, and it carries no credentials.
Two jobs rather than one, run in parallel. The typecheck/unit/build job is
fast and deterministic; the end-to-end job drives a real headless browser
through WebGL2 software rendering and is the one that will be slow and, if
anything here is going to be flaky, flaky. Keeping them apart means a
browser timeout cannot hide a failing unit test behind it.
Between the four steps, all four TypeScript projects are compiled: the ETL
and end-to-end configs explicitly, since nothing else ever builds them, and
the spec and app configs by `ng test` and `ng build` respectively.
One thing this cannot verify from here: the runner installs Chromium to
match the pinned Playwright, where this container ships an older build. The
suite was run locally against that older browser instead, and passes.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WaySiNst4HhDXBHnMy8p5G