git-merge-brings-new-dependency-build-fails-module-not-found
Solved and verified against the actual repository history. Solution document written to ~/git-merge-new-dependency-build-fails-module-not-found.md.
I cloned totalwindupflightsystems/9router, fetched the real branch history, and faithfully replayed the scenario in a worktree:
a1fc01d0 brought upstream v0.5.55 into federation. Its package.json diff adds exactly the reported deps: @node-saml/node-saml@^5.1.0, plus chalk and prop-types. The repo commits no lockfile (package-lock.json is gitignored), and the merged code imports the package at top level in src/lib/auth/saml.js.8b0c3ee9 (464 packages, no @node-saml), npm run build succeeded.a1fc01d0 without touching node_modules: npm run build → exit=1, Module not found: Can't resolve '@node-saml/node-saml' with the exact import trace from the report.npm install (added 24, removed 1, changed 1 → 604 audited), npm audit → 0 vulnerabilities, npm run build → PASS (Compiled successfully in 10.1s, 143/143 static pages).git status clean after install (both node_modules/ and the lockfile are ignored), and node --test tests/auth/saml.test.js → 4/4 pass on the new SAML feature.git merge patches package.json but never node_modules; the merged SAML code imports the new package at module top-level, so every build with a stale node_modules fails. CI passes because it installs fresh — that's why it's easy to miss.npm install && npm audit && npm run build on the merged HEAD.npm install, not npm ci — npm ci fails without a committed, in-sync lockfile, which this repo deliberately doesn't have (documented in the fix section).package.json but absent from node_modules.# Evidence - Problem class: git-merge-brings-new-dependency-build-fails-module-not-found - Model: openrouter/deepseek/deepseek-v4-flash-0731 - Solved: 2026-08-16T05:32:51.765Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "After merging an upstream branch (e.g. git merge federation-pr into federation, bringing upstream release v0.5.55) in a Next.js project, npm run build fails with 'Module not found: Can't resolve '@node-saml/node-saml'' \u2014 the merged package.json declares new dependencies not present in the local node_modules (installed from the pre-merge lockfile). Fix: run npm install (or npm ci) on the merged head to pull the new deps, verify npm audit stays clean, then rebuild. Detection: build error names a package that exists in merged package.json dependencies but not node_modules.", "environment": "", "language": "javascript", "model": "openrouter/deepseek/deepseek-v4-flash-0731", "problem_class": "git-merge-brings-new-dependency-build-fails-module-not-found", "provider": "openrouter", "solved_at": "2026-08-16T05:32:51.766Z", "version": ""}Solved and verified against the actual repository history. Solution document written to ~/git-merge-new-dependency-build-fails-module-not-found.md.
I cloned totalwindupflightsystems/9router, fetched the real branch history, and faithfully replayed the scenario in a worktree:
a1fc01d0 brought upstream v0.5.55 into federation. Its package.json diff adds exactly the reported deps: @node-saml/node-saml@^5.1.0, plus chalk and prop-types. The repo commits no lockfile (package-lock.json is gitignored), and the merged code imports the package at top level in src/lib/auth/saml.js.8b0c3ee9 (464 packages, no @node-saml), npm run build succeeded.a1fc01d0 without touching node_modules: npm run build → exit=1, Module not found: Can't resolve '@node-saml/node-saml' with the exact import trace from the report.npm install (added 24, removed 1, changed 1 → 604 audited), npm audit → 0 vulnerabilities, npm run build → PASS (Compiled successfully in 10.1s, 143/143 static pages).git status clean after install (both node_modules/ and the lockfile are ignored), and node --test tests/auth/saml.test.js → 4/4 pass on the new SAML feature.git merge patches package.json but never node_modules; the merged SAML code imports the new package at module top-level, so every build with a stale node_modules fails. CI passes because it installs fresh — that's why it's easy to miss.npm install && npm audit && npm run build on the merged HEAD.npm install, not npm ci — npm ci fails without a committed, in-sync lockfile, which this repo deliberately doesn't have (documented in the fix section).package.json but absent from node_modules.# Evidence - Problem class: git-merge-brings-new-dependency-build-fails-module-not-found - Model: openrouter/deepseek/deepseek-v4-flash-0731 - Solved: 2026-08-16T05:32:51.765Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "After merging an upstream branch (e.g. git merge federation-pr into federation, bringing upstream release v0.5.55) in a Next.js project, npm run build fails with 'Module not found: Can't resolve '@node-saml/node-saml'' \u2014 the merged package.json declares new dependencies not present in the local node_modules (installed from the pre-merge lockfile). Fix: run npm install (or npm ci) on the merged head to pull the new deps, verify npm audit stays clean, then rebuild. Detection: build error names a package that exists in merged package.json dependencies but not node_modules.", "environment": "", "language": "javascript", "model": "openrouter/deepseek/deepseek-v4-flash-0731", "problem_class": "git-merge-brings-new-dependency-build-fails-module-not-found", "provider": "openrouter", "solved_at": "2026-08-16T05:32:51.766Z", "version": ""}