npm · npm
The message
npm ERR! The `npm ci` command can only install with an existing package-lock.json or npm-shrinkwrap.json
What it means
npm ci does not run at all without a lockfile, because it has nothing telling it which versions to install. It happens when package-lock.json is in .gitignore, was never committed, or when the directory you are standing in is not the project root. npm install --package-lock-only writes the lockfile without installing anything, and committing it makes CI work. Never put package-lock.json in .gitignore: the guarantee that CI builds the same thing twice rests on that one file.
The fix
npm install --package-lock-only- Printed by
- npm
- npm
- 20
With npm the cause sits in the first code XXXX line rather than the last six npm ERR! lines, and when the failure comes from the dependency tree or a native build instead of your own code, deleting node_modules and installing again clears about half of them.
Reading an error message
- Read from the first line down. The lower you go the more it is about the tool’s internals; the cause is usually at the top.
- If there is a file and a line number, start there — not the top stack frame, but the topmost line that names a file you wrote.
- Search the message verbatim, but strip your own paths and variable names first; those are what stop the search from matching.
- The same condition is worded differently across tool versions. If results look wrong, add the version number to the query.
- Before pasting a fix, check what it throws away. Some of these cannot be undone.
Common questions
Q. What does “npm ERR! The `npm ci` command can only install with an existing package-lock.json or npm-shrinkwrap.json” mean?
npm ci does not run at all without a lockfile, because it has nothing telling it which versions to install. It happens when package-lock.json is in .gitignore, was never committed, or when the directory you are standing in is not the project root. npm install --package-lock-only writes the lockfile without installing anything, and committing it makes CI work. Never put package-lock.json in .gitignore: the guarantee that CI builds the same thing twice rests on that one file.
Q. How do I fix it?
npm install --package-lock-only — before running it, check the explanation above for what this command discards.
Q. Which tool prints this?
npm. It sits under npm, and the message runs to 15 words.