Source code
Code quality
Releases
Stability
Lockfile out of sync with manifest
Part of the Dependency supply chain check · fix arrives as a pull request
What it is
The lockfile and the manifest disagree — a dependency or version range was changed without regenerating the lock.
Why it matters
Whichever the install honours, one of the two files is lying about what you ship. A frozen-lockfile install fails outright, and a normal install quietly resolves something neither file describes.
How to fix it
Run an install locally to regenerate the lockfile and commit both files together. Adding a frozen-lockfile install to CI keeps the pair from drifting apart again.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.