Source code Code quality Releases Stability

Lockfile out of sync with manifest

Part of the Dependency supply chain check · fix arrives as a pull request

What it is

The lockfile and the manifest disagree — a dependency or version range was changed without regenerating the lock.

Why it matters

Whichever the install honours, one of the two files is lying about what you ship. A frozen-lockfile install fails outright, and a normal install quietly resolves something neither file describes.

How to fix it

Run an install locally to regenerate the lockfile and commit both files together. Adding a frozen-lockfile install to CI keeps the pair from drifting apart again.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.