aboutsummaryrefslogtreecommitdiffstats
path: root/app
diff options
context:
space:
mode:
authorMark Stacey <markjstacey@gmail.com>2019-07-31 02:36:23 +0800
committerGitHub <noreply@github.com>2019-07-31 02:36:23 +0800
commit1fd3dc9ecf16f00d721078e114138e529a7b8e16 (patch)
treeeec89c15e0ab57173f24931ba286f972c4c97936 /app
parent618c1caf407d5497f4c7ba793f9163640b007e03 (diff)
downloadtangerine-wallet-browser-1fd3dc9ecf16f00d721078e114138e529a7b8e16.tar
tangerine-wallet-browser-1fd3dc9ecf16f00d721078e114138e529a7b8e16.tar.gz
tangerine-wallet-browser-1fd3dc9ecf16f00d721078e114138e529a7b8e16.tar.bz2
tangerine-wallet-browser-1fd3dc9ecf16f00d721078e114138e529a7b8e16.tar.lz
tangerine-wallet-browser-1fd3dc9ecf16f00d721078e114138e529a7b8e16.tar.xz
tangerine-wallet-browser-1fd3dc9ecf16f00d721078e114138e529a7b8e16.tar.zst
tangerine-wallet-browser-1fd3dc9ecf16f00d721078e114138e529a7b8e16.zip
Switch from `npm` to `yarn` (#6843)
As a solution to the constant lockfile churn issues we've had with `npm`, the project now uses `yarn` to manage dependencies. The `package-lock.json` file has been replaced with `yarn.lock`, which was created using `yarn import`. It should approximate the contents of `package-lock.json` fairly well, though there may be some changes due to deduplication. The codeowners file has been updated to reference this new lockfile. All documentation and npm scripts have been updated to reference `yarn` rather than `npm`. Note that running scripts using `npm run` still works fine, but it seemed better to switch those to `yarn` as well to avoid confusion. The `npm-audit` Bash script has been replaced with `yarn-audit`. The output of `yarn audit` is a bit different than `npm audit` in that it returns a bitmask to describe which severity issues were found. This made it simpler to check the results directly from the Bash script, so the associated `npm-audit-check.js` script was no longer required. The output should be exactly the same, and the information is still sourced from the same place (the npm registry). The new `yarn-audit` script does have an external dependency: `jq`. However, `jq` is already assumed to be present by another CI script, and is present on all CI images we use. `jq` was not added to `package.json` as a dependency because there is no official package on the npm registry, just wrapper scripts. We don't need it anywhere exept on CI anyway. The section in `CONTRIBUTING` about how to develop inside the `node_modules` folder was removed, as the advice was a bit dated, and wasn't specific to this project anyway.
Diffstat (limited to 'app')
0 files changed, 0 insertions, 0 deletions