Skip to content
Back to skills

Lockfile Fix

ASecurity

Resolve lockfile drift or merge conflicts by regenerating the lockfile from the manifest

  • 3 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 3, 2026
ai-agentsgo

Security analysis

A92/100
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro shows the line behind each finding and how to fix it

Scanned September 3, 2026

npx -y skills add black141312/ada --skill lockfile-fix --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Lockfile Fix?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Lockfile Fix
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/black141312-lockfile-fix/badge)](https://www.skillsdirectory.com/skills/black141312-lockfile-fix)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: lockfile-fix
description: Resolve lockfile drift or merge conflicts by regenerating the lockfile from the manifest
category: dependencies
---

# Lockfile Fix

Reach for this when the lockfile is out of sync with the manifest or has merge-conflict markers after a rebase/merge.

1. Identify the manager and its lockfile (`package-lock.json`, `pnpm-lock.yaml`, `yarn.lock`, `Cargo.lock`, `poetry.lock`, `uv.lock`).
2. For a merge conflict, take the manifest's resolution first — accept both sides of the manifest, then discard the conflicted lockfile body.
3. Regenerate from the manifest: `npm install`, `pnpm install`, `yarn install`, `cargo generate-lockfile`, `poetry lock`, `uv lock` — never resolve lockfile markers by hand.
4. Verify the manifest itself merged cleanly and reflects the intended versions before regenerating.
5. Reinstall clean (`npm ci`) to prove the new lockfile resolves and the tree installs.
6. Commit the regenerated lockfile alongside the manifest and run tests.

## Rules
- Never hand-edit conflict markers in a lockfile; delete the conflicted content and regenerate.
- Resolve the manifest first — the lockfile is derived, not authoritative.
- Use the same package-manager version as the team/CI; a different version can rewrite the whole lockfile.
- Run a clean install (`ci`/frozen) afterward to catch an unsatisfiable resolution early.
- Keep the regenerated lockfile and manifest in one commit so the pair stays consistent.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…