# npm ELOCKVERIFY / "Errors were found in your package-lock.json" - Fix in CI

> Fix npm lockfile verification errors in CI - "Errors were found in your package-lock.json, run npm install to fix them" - caused by a corrupt, hand-edited, or merge-mangled lockfile.

Source: https://latchkey.dev/learn/node-js/npm-elockverify-lockfile-corrupt  
Updated: 2026-06-25

A lockfile-verification failure means npm found `package-lock.json` internally inconsistent - missing entries, mismatched integrity, or merge damage - so it cannot trust the lock to install from.

## Diagnose it: reproduce the CI install locally

Install failures are usually environment drift rather than a broken lockfile: a different package-manager major, a different Node version, or a cache that is being restored from a run with different inputs. Reproduce the CI conditions before changing the lockfile, because regenerating it hides the real cause.

```Terminal
# match the runner exactly, then install from a clean slate
node --version && npm --version
rm -rf node_modules
npm ci --foreground-scripts

# if that succeeds locally but fails in CI, the difference is the cache
# or the package-manager version, not your lockfile
```

> Pin the package manager with Corepack (`"packageManager"` in package.json) so the runner and every developer machine resolve the same version. Version skew is the single most common source of lockfile errors that only appear in CI.

## Verify the fix survives a cold cache

A green run immediately after a fix often proves nothing, because it restored a cache written before the change. Force a cold install once to confirm the fix is real.

```.github/workflows/ci.yml
# temporarily bust the cache key to prove the fix on a cold runner
- uses: actions/setup-node@v4
  with:
    node-version: 22
    cache: npm
    cache-dependency-path: package-lock.json
# then bump this suffix once, run, and remove it
#   key: ${{ runner.os }}-node-${{ hashFiles('package-lock.json') }}-v2
```

## FAQ

### What causes npm ELOCKVERIFY / "Errors were found in your package-lock.json"?

There are 2 common causes: a merge-mangled or hand-edited lockfile and a truncated or partially written lockfile. Resolving a package-lock.json conflict by hand, or editing it manually, easily produces an inconsistent tree npm cannot verify.

### How do I fix npm ELOCKVERIFY / "Errors were found in your package-lock.json"?

There are 2 fixes depending on which cause you have: regenerate the lockfile cleanly and keep ci on npm ci. Work through them in order, since the first is the most common.

### What does npm ELOCKVERIFY / "Errors were found in your package-lock.json" actually mean?

npm ci (or install) reports that errors were found in package-lock.json and asks you to run npm install to fix them.

### How do I stop npm ELOCKVERIFY / "Errors were found in your package-lock.json" happening again?

Always regenerate the lockfile instead of hand-merging. The prevention section lists 3 changes that keep it from recurring.

---

Latchkey runs CI/CD that repairs its own failures. Agent entry points: https://latchkey.dev/agent.txt, https://latchkey.dev/openapi.json, https://latchkey.dev/llms.txt
