Bug 11902 - updating npm4 to npm5
Summary: updating npm4 to npm5
Status: RESOLVED FIXED
Alias: None
Product: OE-Core
Classification: Build System, Metadata & Runtime
Component: core (show other bugs)
Version: unspecified
Hardware: x86 Multiple
: Medium normal
Target Milestone: Future
Assignee: Unassigned
QA Contact:
URL:
Whiteboard:
Depends on:
Blocks: 10653
  Show dependency tree
 
Reported: 2017-08-06 23:37 UTC by Stanley Phoong
Modified: 2020-05-17 02:40 UTC (History)
7 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: No (bug/feature does not impact docs)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stanley Phoong 2017-08-06 23:37:27 UTC

    
Comment 1 Paul Eggleton 2017-08-17 00:27:19 UTC
Stanley - can you please include some brief details based on our earlier discussion about the motivations for this upgrade and then reassign it back to me? Thanks.
Comment 2 Stanley Phoong 2017-08-20 23:53:58 UTC
sorry about that Paul, sure thing.
npm@4 lacking a few feature that would ease up the bitbake fetcher process:

- Has faster installs
- Offline support (if you already installed the modules)
- Lock file for deterministic installs

Hence, using Yarn and npm@5 as a possible alternative is considered to tackle these issues.

After some discussions with Paul here's some summary:

Yarn would require too much change internally in order to adopt Yarn and Yarn would also require a different workflow.

npm@5 requires lesser changes but doesn't mean that there's no change required. npm@5 has all three features that Yarn also provides including lock file to lock the versions of the dependencies.

Simply running a simple "npm install" would automatically trigger the package-lock.json file to be write the version into. No longer a need to explicitly call npm strinkwrap and etc...

The introduction of "package-lock.json, is a new, standardised lockfile feature meant for cross-package-manager compatibility (package-lock.json), and a new format and semantics for shrinkwrap.

The other good news is the installation now take approximately half the original time taken by npm@4.

Additionally, package-lock.json will be automatically created unless an npm-shrinkwrap.json exists. 

Other new feature is "--prefer-offline" and "--prefer-online", the first option will make npm skip any conditional requests (304 checks) for stale cache data, and only hit the network if something is missing from the cache. While the "prefer-online", option will force npm to revalidate cached data (with 304 checks), ignoring any staleness checks, and refreshing the cache with revalidated, fresh data.

Also, another thing "--save" is no longer necessary, to force an npm install to write into the package.json.

This should ease out a few issues faced with npm@4 especially regarding the lock file and versions.
Comment 3 Henry Bruce 2018-01-10 06:44:59 UTC
Note that only even versions receive LTS (see https://github.com/nodejs/Release#release-schedule), so if investing more effort here, go for v6 or v8.
Comment 4 Jean-Marie Lemetayer 2020-05-17 02:40:27 UTC
Current version:
 - node: 12.14.1
 - npm: 6.13.4