A fresh install of kartotherian (either github or gerrit) with recent npm has the notice
npm notice created a lockfile as package-lock.json. You should commit this file.
Because it'd be useful to have npm install do the same thing every time and not break when external stuff changes, this is probably is a good idea.
We'll want to sort out the various broken package.json things first