diff --git a/.agents/scripts/launch.sh b/.agents/scripts/launch.sh index bf51c11..61612da 100755 --- a/.agents/scripts/launch.sh +++ b/.agents/scripts/launch.sh @@ -56,9 +56,10 @@ else git worktree add "$dir" -b "$branch" "$base" fi -# npm ci only once task 01 has produced a package.json. Before that there is no -# toolchain to install, and no hooks to verify. -if [ -f "$dir/package.json" ]; then +# npm ci only once task 01 has produced a lockfile. The pre-existing root +# package.json carries two scripts and no dependencies, so before task 01 there +# is no toolchain to install and no hooks to verify. +if [ -f "$dir/package-lock.json" ]; then ( cd "$dir" && npm ci --prefer-offline && .agents/scripts/verify-hooks.sh ) fi diff --git a/AGENTS.md b/AGENTS.md index 16f504e..f07fb02 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -49,7 +49,10 @@ Adding a build step changes this contract. Read - `submitted-skills/` — other people's submitted work, reproduced verbatim - `skill-reviews/improved/` — generated; edit `skills-review/catalog.js` instead - `vote-service/` — separate deploy lifecycle; do not fold into the site build -- `package-lock.json`, `dist/`, `node_modules/` +- `dist/`, `node_modules/` — build output, never committed +- `package-lock.json` — **committed, but never hand-edited.** Change it only + as a side effect of `npm install`. Every worktree spins up with `npm ci`, + which fails outright without it. ## Rules