fix(deps): move pnpm overrides to pnpm-workspace.yaml - #96
Conversation
pnpm 11 no longer reads the `pnpm` field from package.json, so the overrides added by the recent dependency sweep were silently ignored while the lockfile still recorded them. The frozen install in CI (which runs pnpm 11) then aborts with: ERR_PNPM_LOCKFILE_CONFIG_MISMATCH Cannot proceed with the frozen installation. The current "overrides" configuration doesn't match the value found in the lockfile That kills the publish job in its "Bump version (patch)" step, so no release can go out. Move the same overrides, unchanged, into pnpm-workspace.yaml where pnpm 11 reads them. The lockfile is unchanged (still lockfileVersion '9.0'), and `--frozen-lockfile` now succeeds under both pnpm 10 (lint job) and pnpm 11 (publish job). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw
|
ⓘ Qodo reviews are paused because the subscription is no longer active. Ask your workspace admin to reactivate the subscription to resume reviews. Manage billing |
Code Review by Qodo
1. Publish regressions can go undetected
|
| # pnpm 11 no longer reads `pnpm.overrides` from package.json — these must live | ||
| # here or the lockfile and the install disagree (ERR_PNPM_LOCKFILE_CONFIG_MISMATCH). | ||
| overrides: | ||
| js-yaml@4: '^4.3.2' |
There was a problem hiding this comment.
1. Publish regressions can go undetected 📘 Rule violation ▣ Testability
pnpm-workspace.yaml relocates the dependency overrides without adding or updating an automated regression test for the frozen-install failure. A later configuration change can therefore recreate the package-manager mismatch without being detected before the publish job runs.
Agent Prompt
## Issue description
This bug fix moves dependency overrides so pnpm 11 can complete a frozen installation, but it adds no automated regression test for the previously failing publish path.
## Fix Focus Areas
- pnpm-workspace.yaml[6-10]
## Recommended Fix
Add an automated CI test that runs the supported pnpm 11 version with `install --frozen-lockfile` and verifies that the configured overrides agree with the lockfile. Name the test or job after the pnpm 11 override-location regression so it would fail against the pre-fix configuration.
ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools
PR Summary by QodoMove pnpm overrides to pnpm 11-compatible workspace configuration
AI Description
Diagram
High-Level Assessment
Files changed (2)
|
Problem
The recent dependency sweep added
pnpm.overridestopackage.json(to clear the js-yaml / brace-expansion advisories) and regenerated the lockfile with pnpm 10.pnpm 11 no longer reads the
pnpmfield frompackage.json. It warns:CI's publish job runs pnpm 11, so it sees no overrides while the lockfile records them, and the frozen install aborts:
The publish job dies in its "Bump version (patch)" step, so this plugin cannot release at all until this is fixed. The dependency fix itself was right; only its location was wrong.
Fix
pnpmkey frompackage.json.pnpm-workspace.yaml, where pnpm 11 reads them, with a comment explaining why the selectors are scoped to a major line and why they can't live inpackage.jsonany more.Verification
pnpm-lock.yamlis byte-for-byte unchanged — stilllockfileVersion: '9.0', so the lint job (pinned to pnpm 10) keeps working.npx -y pnpm@11 i --frozen-lockfile→ succeedspnpm i --frozen-lockfilewith pnpm 10 → succeedsjs-yaml@4.3.2andbrace-expansion@1.1.21(nojs-yaml@4.1.1, nobrace-expansion@1.1.14).pnpm run lint→ 0 errors.🤖 Generated with Claude Code
https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw