Heroku部署旧Node应用时npm ci报错,lockfileVersion=2仍失败
问题
对一个旧Node应用做了微小文本修改,本地npm ci等操作正常,但部署到Heroku时出现错误:
npm ERR! The `npm ci` command can only install with an existing package-lock.json or remote npm-shrinkwrap.json with lockfileVersion >= 1
但本地package-lock.json明确包含:
"lockfileVersion": 2,
该应用之前部署正常,距上次部署已一两年,推测是Heroku buildpack更新导致的问题。当前尝试从heroku-18升级到heroku-22部署,已试过不同Node和NPM版本,但应用是遗留项目,升级Node 12以上需大量修改,希望避免。
完整错误信息
remote: Building source: remote: remote: -----> Building on the Heroku-22 stack remote: -----> Using buildpack: heroku/nodejs remote: -----> Node.js app detected remote: remote: -----> Creating runtime environment remote: remote: NPM_CONFIG_LOGLEVEL=error remote: NODE_VERBOSE=false remote: NODE_ENV=production remote: NODE_MODULES_CACHE=true remote: remote: -----> Installing binaries remote: engines.node (package.json): 15.3.0 remote: engines.npm (package.json): 7.0.14 remote: remote: Resolving node version 15.3.0... remote: Downloading and installing node 15.3.0... remote: npm 7.0.14 already installed with node remote: remote: -----> Restoring cache remote: Cached directories were not restored due to a change in version of node, npm, yarn or stack remote: Module installation may take longer for this build remote: remote: -----> Prebuild remote: Running heroku-prebuild remote: remote: > snazzywiz@2.1.1 heroku-prebuild remote: > npm --global install pushstate-server@3.0.1; npm --global install @angular/cli remote: remote: remote: added 44 packages, and audited 44 packages in 3s remote: remote: 10 vulnerabilities (5 low, 3 moderate, 2 high) remote: remote: To address issues that do not require attention, run: remote: npm audit fix remote: remote: To address all issues, run: remote: npm audit fix --force remote: remote: Run `npm audit` for details. remote: remote: added 209 packages, and audited 209 packages in 8s remote: remote: 25 packages are looking for funding remote: run `npm fund` for details remote: remote: found 0 vulnerabilities remote: npm notice remote: npm notice New major version of npm available! 7.0.14 -> 8.19.2 remote: npm notice Changelog: <https://github.com/npm/cli/releases/tag/v8.19.2> remote: npm notice Run `npm install -g npm@8.19.2` to update! remote: npm notice remote: remote: -----> Installing dependencies remote: Installing node modules remote: npm ERR! The `npm ci` command can only install with an existing package-lock.json or remote: npm ERR! npm-shrinkwrap.json with lockfileVersion >= 1. Run an install with npm@5 or remote: npm ERR! later to generate a package-lock.json file, then try again. remote: remote: npm ERR! A complete log of this run can be found in: remote: npm ERR! /tmp/npmcache.ULXke/_logs/2022-09-17T19_15_54_600Z-debug.log remote: remote: -----> Build failed
解决办法
1. 强制Heroku使用npm install替代npm ci
Heroku默认生产环境用npm ci,但该命令在当前场景下对lockfile识别异常。设置环境变量修改安装行为:
- 执行命令:
heroku config:set USE_NPM_INSTALL=true - 重新部署,
npm install对lockfile版本兼容性更强,可绕过该错误。
2. 降级lockfile版本至1
若需保留npm ci,可将lockfileVersion从2降级到1:
- 本地安装npm 6.x:
npm install -g npm@6 - 删除现有
package-lock.json - 执行
npm install生成lockfileVersion为1的文件 - 提交新的
package-lock.json并重新部署
3. 锁定Heroku Node buildpack到旧版本
新版buildpack可能对旧Node/npm组合兼容性不足,指定旧版本buildpack:
- 选择与上次部署时接近的buildpack版本(比如v18.x系列)
- 执行命令:
heroku buildpacks:set https://github.com/heroku/heroku-buildpack-nodejs#v18.18.0(版本号可按需调整) - 重新部署
4. 回退到heroku-18栈
若升级heroku-22是问题诱因,先回退到原正常栈:
- 执行命令:
heroku stack:set heroku-18 - 重新部署,确认是否恢复正常
内容的提问来源于stack exchange,提问作者Jan Nielsen
相关产品推荐
相关产品推荐

