What it means
package.json lists the packages your project wants. package-lock.json records the exact versions that were installed. The command npm ci installs exactly what the lock file says, and it stops if the two files disagree. Somewhere, a package was added, removed or changed in one file and not the other.
How to fix it
-
Run
npm installon your machineUse the same Node.js version as your project. npm updates
package-lock.jsonso it matchespackage.json. -
Commit the lock file
Commit
package-lock.jsontogether withpackage.json. Check that the lock file is not listed in.gitignore. -
Deploy again
A failed deploy never counts against your plan, so you can try as often as you need.
If you use another package manager, the same idea applies. For Yarn, run yarn install and commit yarn.lock. For pnpm, run pnpm install and commit pnpm-lock.yaml.
Why it happens
-
A coding agent edited
package.jsonand never ran an install. This is the most common cause with AI-written code. -
The lock file came from a different npm version. A newer or older npm can record packages in a way another version rejects.
-
The lock file is in a different folder, or not committed. The build only sees what you send.
What Antideploy does
Antideploy recognises this failure. It installs from package.json for that build, in its own copy of your source, and tells you it did. It never edits your repository. The cost is that a package can resolve to a newer version inside the range your package.json allows, which is not always the version you ran. That is why the right fix is still to commit a matching lock file.