Skip to content

fix(deps): move pnpm overrides to pnpm-workspace.yaml - #155

Merged
JohnMcLear merged 1 commit into
masterfrom
fix/pnpm11-overrides
Sep 21, 2026
Merged

JohnMcLear merged 1 commit into
masterfrom
fix/pnpm11-overrides

Conversation

@JohnMcLear

Copy link
Copy Markdown
Member

Problem

The recent dependency sweep added pnpm.overrides to package.json (to clear the js-yaml / brace-expansion advisories) and regenerated the lockfile with pnpm 10.

pnpm 11 no longer reads the pnpm field from package.json. It warns:

The "pnpm" field in package.json is no longer read by pnpm ... "pnpm.overrides"

CI's publish job runs pnpm 11, so it sees no overrides while the lockfile records them, and the frozen install aborts:

ERR_PNPM_LOCKFILE_CONFIG_MISMATCH
Cannot proceed with the frozen installation. The current "overrides" configuration
doesn't match the value found in the lockfile

The publish job dies in its "Bump version (patch)" step, so this plugin cannot release at all until this is fixed. The dependency fix itself was right; only its location was wrong.

Fix

  • Remove the pnpm key from package.json.
  • Put the same overrides, values unchanged, in pnpm-workspace.yaml, where pnpm 11 reads them, with a comment explaining why the selectors are scoped to a major line and why they can't live in package.json any more.

Verification

  • pnpm-lock.yaml is byte-for-byte unchanged — still lockfileVersion: '9.0', so the lint job (pinned to pnpm 10) keeps working.
  • npx -y pnpm@11 i --frozen-lockfile → succeeds
  • pnpm i --frozen-lockfile with pnpm 10 → succeeds
  • Patched versions survive: js-yaml@4.3.2 and brace-expansion@1.1.21,brace-expansion@5.0.12 (no js-yaml@4.1.1, no brace-expansion@1.1.14).
  • pnpm run lint → 0 errors.

🤖 Generated with Claude Code

https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw

pnpm 11 no longer reads the `pnpm` field from package.json, so the
overrides added by the recent dependency sweep were silently ignored
while the lockfile still recorded them. The frozen install in CI (which
runs pnpm 11) then aborts with:

  ERR_PNPM_LOCKFILE_CONFIG_MISMATCH
  Cannot proceed with the frozen installation. The current "overrides"
  configuration doesn't match the value found in the lockfile

That kills the publish job in its "Bump version (patch)" step, so no
release can go out.

Move the same overrides, unchanged, into pnpm-workspace.yaml where
pnpm 11 reads them. The lockfile is unchanged (still lockfileVersion
'9.0'), and `--frozen-lockfile` now succeeds under both pnpm 10 (lint
job) and pnpm 11 (publish job).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw
@qodo-code-review

Copy link
Copy Markdown

ⓘ Qodo reviews are paused because the subscription is no longer active. Ask your workspace admin to reactivate the subscription to resume reviews. Manage billing

@qodo-free-for-open-source-projects

qodo-free-for-open-source-projects Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (1) 📎 Requirement gaps (0) 🎨 UX issues (0) 🔗 Cross-repo conflicts (0) 📜 Skill insights (0)

Grey Divider


Remediation recommended

1. Release fix lacks a regression guard 📘 Rule violation ▣ Testability
Description
pnpm-workspace.yaml relocates the overrides that fix the pnpm 11 frozen-install failure, but the
change adds no automated check that runs that previously failing installation. Because the existing
lint job pins pnpm 10 and only the publishing workflow invokes pnpm 11, the configuration mismatch
can return without being detected before the release workflow runs.
Code

pnpm-workspace.yaml[R6-9]

+# pnpm 11 no longer reads `pnpm.overrides` from package.json — these must live
+# here or the lockfile and the install disagree (ERR_PNPM_LOCKFILE_CONFIG_MISMATCH).
+overrides:
+  js-yaml@^4: '>=4.3.2 <5'
Evidence
PR Compliance ID 565485 requires every bug fix to add or modify an automated regression test that
fails before the fix and runs in the normal suite. The added workspace configuration is explicitly
identified as the fix for the pnpm 11 lockfile mismatch, while the change set contains no test or CI
modification exercising a pnpm 11 frozen install.

Rule 565485: Every bug fix must include a regression test in the same change
pnpm-workspace.yaml[6-10]
.github/workflows/lint.yml[19-35]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The override relocation fixes a pnpm 11 frozen-install failure without adding an automated regression check for that scenario.
## Fix Focus Areas
- pnpm-workspace.yaml[6-10]
- .github/workflows/lint.yml[19-35]
## Recommended Fix
Add a normal CI job or matrix entry that installs pnpm 11 and runs `pnpm install --frozen-lockfile`. Ensure the check runs for pull requests so restoring the overrides to an unsupported location would fail before merge.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Tip of the day
💡 Did you know, you can add REVIEW.md to your repo root and Qodo follows it on every PR

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

Comment thread pnpm-workspace.yaml
Comment on lines +6 to +9
# pnpm 11 no longer reads `pnpm.overrides` from package.json — these must live
# here or the lockfile and the install disagree (ERR_PNPM_LOCKFILE_CONFIG_MISMATCH).
overrides:
js-yaml@^4: '>=4.3.2 <5'

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remediation recommended

1. Release fix lacks a regression guard 📘 Rule violation ▣ Testability

pnpm-workspace.yaml relocates the overrides that fix the pnpm 11 frozen-install failure, but the
change adds no automated check that runs that previously failing installation. Because the existing
lint job pins pnpm 10 and only the publishing workflow invokes pnpm 11, the configuration mismatch
can return without being detected before the release workflow runs.
Agent Prompt
## Issue description
The override relocation fixes a pnpm 11 frozen-install failure without adding an automated regression check for that scenario.

## Fix Focus Areas
- pnpm-workspace.yaml[6-10]
- .github/workflows/lint.yml[19-35]

## Recommended Fix
Add a normal CI job or matrix entry that installs pnpm 11 and runs `pnpm install --frozen-lockfile`. Ensure the check runs for pull requests so restoring the overrides to an unsupported location would fail before merge.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

PR Summary by Qodo

Move pnpm overrides to workspace configuration

🐞 Bug fix ⚙️ Configuration changes 🕐 Less than 10 minutes

Grey Divider

AI Description

• Relocates security overrides to pnpm 11's supported workspace configuration.
• Preserves scoped dependency versions and existing lockfile compatibility.
• Restores frozen installs across pnpm 10 lint and pnpm 11 publishing.
Diagram

sequenceDiagram
    participant CI as CI Jobs
    participant PNPM as pnpm 10/11
    participant PKG as package.json
    participant WS as pnpm-workspace.yaml
    participant LOCK as pnpm-lock.yaml
    CI->>PNPM: Frozen install
    PNPM->>PKG: Read package metadata
    PNPM->>WS: Read overrides
    PNPM->>LOCK: Validate settings
    LOCK-->>PNPM: Configuration matches
    PNPM-->>CI: Install succeeds
Loading
High-Level Assessment

The selected approach is optimal because pnpm-workspace.yaml is the supported override location for pnpm 11 while remaining compatible with pnpm 10. Pinning publishing to pnpm 10 would only defer the incompatibility, and regenerating the lockfile would not resolve pnpm 11 ignoring package.json overrides.

Files changed (2) +10 / -6

Other (2) +10 / -6
package.jsonRemove deprecated package-level pnpm overrides +0/-6

Remove deprecated package-level pnpm overrides

• Removes the pnpm.overrides block that pnpm 11 no longer reads. Package metadata and dependency declarations remain unchanged.

package.json

pnpm-workspace.yamlDefine scoped dependency overrides in workspace configuration +10/-0

Define scoped dependency overrides in workspace configuration

• Adds the existing js-yaml and brace-expansion security overrides in pnpm's cross-version configuration location. Comments document the transitive dependency constraints, major-version scoping, and pnpm 11 compatibility requirement.

pnpm-workspace.yaml

@JohnMcLear
JohnMcLear merged commit 8645aad into master Sep 21, 2026
6 checks passed
@JohnMcLear
JohnMcLear deleted the fix/pnpm11-overrides branch September 21, 2026 18:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant