Skip to content

fix(deps): move pnpm overrides to pnpm-workspace.yaml - #99

Merged
JohnMcLear merged 1 commit into
mainfrom
fix/pnpm11-overrides
Sep 21, 2026
Merged

JohnMcLear merged 1 commit into
mainfrom
fix/pnpm11-overrides

Conversation

@JohnMcLear

Copy link
Copy Markdown
Member

Problem

The recent dependency sweep added pnpm.overrides to package.json to clear the js-yaml / brace-expansion advisories, and regenerated the lockfile with pnpm 10.

pnpm 11 no longer reads the pnpm field from package.json. It warns:

The "pnpm" field in package.json is no longer read by pnpm ... "pnpm.overrides"

and ignores it. CI's publish job runs pnpm 11, so it sees no overrides while the lockfile records them, and the frozen install aborts:

ERR_PNPM_LOCKFILE_CONFIG_MISMATCH
Cannot proceed with the frozen installation. The current "overrides" configuration
doesn't match the value found in the lockfile

The publish job dies in its "Bump version (patch)" step, so this plugin cannot release until it is fixed.

Fix

The dependency fix itself was right; only its location was wrong. This moves the overrides verbatim from package.json into pnpm-workspace.yaml, which both pnpm 10 (used by the lint job) and pnpm 11 (used by publish) read.

Verification

  • npx -y pnpm@11 install → Lockfile is up to date, resolution step is skipped; lockfileVersion: '9.0' unchanged
  • npx -y pnpm@11 i --frozen-lockfile → succeeds
  • pnpm i --frozen-lockfile with pnpm 10 → succeeds
  • Patched versions still resolve; no js-yaml@4.1.1 or brace-expansion@1.1.14 in the lockfile
  • pnpm run lint → 0 errors

🤖 Generated with Claude Code

https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw

pnpm 11 no longer reads the `pnpm` field from package.json, so the
overrides added to clear the js-yaml / brace-expansion advisories were
silently ignored while the lockfile still recorded them. The frozen
install in CI then aborted with ERR_PNPM_LOCKFILE_CONFIG_MISMATCH,
which blocked the publish job at "Bump version (patch)".

Move the overrides verbatim into pnpm-workspace.yaml, where pnpm 10 and
pnpm 11 both read them. The lockfile is unchanged (lockfileVersion 9.0)
and the patched versions still resolve.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw
@qodo-code-review

Copy link
Copy Markdown

ⓘ Qodo reviews are paused because the subscription is no longer active. Ask your workspace admin to reactivate the subscription to resume reviews. Manage billing

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can add REVIEW.md to your repo root and Qodo follows it on every PR

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

PR Summary by Qodo

Move pnpm overrides to the pnpm 11-compatible workspace config

🐞 Bug fix ⚙️ Configuration changes 🕐 Less than 10 minutes

Grey Divider

AI Description

• Relocates security overrides to the configuration read by pnpm 10 and 11.
• Restores frozen CI installs and unblocks package publishing without changing dependency
 resolution.
Diagram

graph TD
  P10["pnpm 10"] --> W["Workspace overrides"] --> L[("Lockfile config")] --> I["Frozen install"] --> C["CI publish"]
  P11["pnpm 11"] --> W
Loading
High-Level Assessment

The selected approach is optimal: pnpm-workspace.yaml is the canonical override location recognized by both pnpm 10 and 11. Regenerating the lockfile or pinning CI to pnpm 10 would only mask the configuration mismatch rather than provide forward-compatible package-manager behavior.

Files changed (2) +10 / -6

Bug fix (1) +10 / -0
pnpm-workspace.yamlDefine scoped dependency overrides in workspace configuration +10/-0

Define scoped dependency overrides in workspace configuration

• Adds the existing js-yaml and brace-expansion overrides at the workspace level for pnpm 10 and 11 compatibility. Comments document the transitive dependency constraints and frozen-lockfile mismatch being prevented.

pnpm-workspace.yaml

Other (1) +0 / -6
package.jsonRemove deprecated package-level pnpm overrides +0/-6

Remove deprecated package-level pnpm overrides

• Removes the pnpm.overrides field that pnpm 11 ignores. Dependency declarations and resolved versions remain unchanged.

package.json

@JohnMcLear
JohnMcLear merged commit ca49ad6 into main Sep 21, 2026
4 checks passed
@JohnMcLear
JohnMcLear deleted the fix/pnpm11-overrides branch September 21, 2026 18:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant