Is there an existing issue for this?
This issue exists in the latest npm version
Current Behavior
I need to do npm install twice to have the correct package-lock.json
Expected Behavior
package-lock.json is good on first npm install
Steps To Reproduce
- Download repro repo: https://github.com/Saibamen/npm-bug-repro-workspaces
npm run clean:all (delete all node_modules folders + lock files)
npm install
npm audit --omit=dev
- ❌ See vulnerabilities from lodash package
npm run clean (delete node_modules and lock file, but only in root folder)
npm install
npm audit --omit=dev
- ❎ No vulnerabilities and changed lock file
Environment
; node bin location = C:\nvm4w\nodejs\node.exe
; node version = v24.14.0
; npm local prefix = C:\DEV\test_npm
; npm version = 11.12.0
; cwd = C:\DEV\test_npm
; HOME = C:\Users\AdamStachowicz
Is there an existing issue for this?
This issue exists in the latest npm version
Current Behavior
I need to do
npm installtwice to have the correctpackage-lock.jsonExpected Behavior
package-lock.jsonis good on firstnpm installSteps To Reproduce
npm run clean:all(delete allnode_modulesfolders + lock files)npm installnpm audit --omit=devnpm run clean(deletenode_modulesand lock file, but only in root folder)npm installnpm audit --omit=devEnvironment