From 1998cdae24463b41ed01036ff0105be296be00aa Mon Sep 17 00:00:00 2001 From: loki5512344 Date: Mon, 28 Sep 2026 15:30:42 +0200 Subject: [PATCH] fix(deploy): use bun --frozen-lockfile instead of npm install MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit npm install with no committed package-lock.json re-resolved semver ranges fresh on every deploy instead of pinning to bun.lock (the project's actual lockfile) — a supply-chain integrity gap flagged by automated commit review. Use bun, the frontend's real package manager, with --frozen-lockfile so deploys are reproducible. Claude-Session: https://claude.ai/code/session_01F1M1Jic1wTSn4igUENynmZ --- backend/deploy/deploy.sh | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/backend/deploy/deploy.sh b/backend/deploy/deploy.sh index a715339..99ec810 100755 --- a/backend/deploy/deploy.sh +++ b/backend/deploy/deploy.sh @@ -14,8 +14,8 @@ docker compose -f docker-compose.prod.yml up -d --build echo "==> Building frontend" cd "$REPO_DIR/frontend" -npm install -npm run build +bun install --frozen-lockfile +bun run build echo "==> Syncing frontend build to $FRONTEND_ROOT" mkdir -p "$FRONTEND_ROOT"