From b00af3022aed1c49e700a1244ce663d880cd113c Mon Sep 17 00:00:00 2001
From: Rhys Arkins <rhys@arkins.net>
Date: Thu, 22 Feb 2018 07:42:59 +0100
Subject: [PATCH] fix: re-enable package-lock-only for npm

Closes #1531
---
 lib/workers/branch/lerna.js | 2 +-
 lib/workers/branch/npm.js   | 2 +-
 2 files changed, 2 insertions(+), 2 deletions(-)

diff --git a/lib/workers/branch/lerna.js b/lib/workers/branch/lerna.js
index 29ccfff9f6..b4f85b864f 100644
--- a/lib/workers/branch/lerna.js
+++ b/lib/workers/branch/lerna.js
@@ -23,7 +23,7 @@ async function generateLockFiles(manager, tmpDir, env) {
     logger.debug('Using lerna version ' + lernaVersion);
     const params =
       manager === 'npm'
-        ? '--ignore-scripts'
+        ? '--package-lock-only'
         : '--ignore-scripts --ignore-engines --ignore-platform --mutex network:31879';
     const cmd = `${manager} install ${params} && npx lerna@${lernaVersion} bootstrap -- ${params}`;
     logger.debug({ cmd });
diff --git a/lib/workers/branch/npm.js b/lib/workers/branch/npm.js
index 5875fc31be..4ce710ca4a 100644
--- a/lib/workers/branch/npm.js
+++ b/lib/workers/branch/npm.js
@@ -53,7 +53,7 @@ async function generateLockFile(tmpDir, env) {
       }
     }
     logger.debug(`Using npm: ${cmd}`);
-    cmd = `ls -l && ${cmd} --version && ${cmd} install --ignore-scripts`;
+    cmd = `ls -l && ${cmd} --version && ${cmd} install --package-lock-only`;
     // TODO: Switch to native util.promisify once using only node 8
     ({ stdout, stderr } = await exec(cmd, {
       cwd: tmpDir,
-- 
GitLab