agent's upgrade script ran npm install with --force to "fix" a peer conflict and shipped the forced tree to production
Fixes agents that run `npm install --force` to silence a peer conflict and ship the resulting invalid tree to production. Use when a forced install papered over ERESOLVE. Key trigger: `--force` or `--legacy-peer-deps` appears in install or deploy scripts.
TL;DR: --force does not fix peer conflicts, it silences them: npm installs a tree it knows is invalid and you ship the breakage. Resolve the conflict properly - upgrade the peer, add a documented override, or pin - and ban force flags in CI and deploy scripts so no future run can silently force.
agent's upgrade script ran npm install with --force to "fix" a peer conflict and shipped the forced tree to production- Assess the damage: inspect what the forced tree actually installed (
npm ls [pkg]). Expected: peer dependencies that do not satisfy the declared ranges - the conflict is still there, just installed anyway. - Reproduce the real conflict without the flag: fresh install with no
--force. Expected: the original ERESOLVE error, showing the true conflict the flag hid. - Resolve it for real: upgrade the conflicting peer, add a scoped override with a recorded reason, or pin the versions. Expected: a clean install with no force flag and no peer warnings.
- Ban the flag: search deploy and CI scripts for
--forceand--legacy-peer-deps, and add a CI check that fails if either appears. Expected: future runs cannot silently force an install. - Verify production: if the forced tree shipped, check logs for runtime errors from mismatched peers and roll forward with the fixed tree. Expected: no peer-mismatch errors after the corrected deploy.
Use this when
--forceor--legacy-peer-depswas used to "resolve" a peer conflict- Production shows errors from mismatched peer versions
- You need to forbid force flags in automation
- An ERESOLVE was "fixed" without changing any version
Not for this skill when
- The flag use is legitimate (for example overwriting a local install dir)
- The conflict was resolved via a documented override
- You are debugging the ERESOLVE itself rather than the force-flag abuse
Variant phrasings
- npm install --force shipped to production
- --force hid peer dependency conflict
- Forced install broke production
- --legacy-peer-deps papered over ERESOLVE
Why it happens
--force tells npm to skip the consistency checks that exist to protect you. The install "succeeds", CI is green, and the invalid tree - two copies of a framework, a plugin against the wrong peer - ships. The failure then appears at runtime, far from the install step that caused it, and nothing in the pipeline connects the runtime crash back to the forced install.
Edge cases
--legacy-peer-depsis the same sin with a nicer name - ban both- Overrides are the sanctioned escape hatch, but they must be documented or the next agent removes them
- Some base images bake in a forced install - rebuild the image rather than layering fixes on top
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_eJFD3LLi9zpjUQ4fTgaHWw
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.