fix(deploy): use bun --frozen-lockfile instead of npm install
npm install with no committed package-lock.json re-resolved semver ranges fresh on every deploy instead of pinning to bun.lock (the project's actual lockfile) — a supply-chain integrity gap flagged by automated commit review. Use bun, the frontend's real package manager, with --frozen-lockfile so deploys are reproducible. Claude-Session: https://claude.ai/code/session_01F1M1Jic1wTSn4igUENynmZ
This commit is contained in:
parent
4c2486d7cd
commit
1998cdae24
1 changed files with 2 additions and 2 deletions
|
|
@ -14,8 +14,8 @@ docker compose -f docker-compose.prod.yml up -d --build
|
|||
|
||||
echo "==> Building frontend"
|
||||
cd "$REPO_DIR/frontend"
|
||||
npm install
|
||||
npm run build
|
||||
bun install --frozen-lockfile
|
||||
bun run build
|
||||
|
||||
echo "==> Syncing frontend build to $FRONTEND_ROOT"
|
||||
mkdir -p "$FRONTEND_ROOT"
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue