Source code Code quality Releases

Mixed package managers

Part of the Dependency supply chain check · fix arrives as a pull request

What it is

The repository contains lockfiles from more than one package manager — for example both package-lock.json and pnpm-lock.yaml.

Why it matters

Different tools resolve to different trees, so what CI builds depends on which command ran. The stale lockfile also keeps being updated by whoever uses that tool, which makes the disagreement permanent.

How to fix it

Pick one package manager, delete the other lockfiles, and declare the choice in packageManager so tooling and contributors follow it automatically.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.