Do not publish package-lock.json

Commit it, but don't publish it, since it'll be ignored anyway:

"One key detail about package-lock.json is that it cannot be
published, and it will be ignored if found in any place other
than the toplevel package."
