fix(deps): move pnpm overrides to pnpm-workspace.yaml - #155
Conversation
pnpm 11 no longer reads the `pnpm` field from package.json, so the overrides added by the recent dependency sweep were silently ignored while the lockfile still recorded them. The frozen install in CI (which runs pnpm 11) then aborts with: ERR_PNPM_LOCKFILE_CONFIG_MISMATCH Cannot proceed with the frozen installation. The current "overrides" configuration doesn't match the value found in the lockfile That kills the publish job in its "Bump version (patch)" step, so no release can go out. Move the same overrides, unchanged, into pnpm-workspace.yaml where pnpm 11 reads them. The lockfile is unchanged (still lockfileVersion '9.0'), and `--frozen-lockfile` now succeeds under both pnpm 10 (lint job) and pnpm 11 (publish job). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw
|
ⓘ Qodo reviews are paused because the subscription is no longer active. Ask your workspace admin to reactivate the subscription to resume reviews. Manage billing |
Code Review by Qodo
1. Release fix lacks a regression guard
|
| # pnpm 11 no longer reads `pnpm.overrides` from package.json — these must live | ||
| # here or the lockfile and the install disagree (ERR_PNPM_LOCKFILE_CONFIG_MISMATCH). | ||
| overrides: | ||
| js-yaml@^4: '>=4.3.2 <5' |
There was a problem hiding this comment.
1. Release fix lacks a regression guard 📘 Rule violation ▣ Testability
pnpm-workspace.yaml relocates the overrides that fix the pnpm 11 frozen-install failure, but the change adds no automated check that runs that previously failing installation. Because the existing lint job pins pnpm 10 and only the publishing workflow invokes pnpm 11, the configuration mismatch can return without being detected before the release workflow runs.
Agent Prompt
## Issue description
The override relocation fixes a pnpm 11 frozen-install failure without adding an automated regression check for that scenario.
## Fix Focus Areas
- pnpm-workspace.yaml[6-10]
- .github/workflows/lint.yml[19-35]
## Recommended Fix
Add a normal CI job or matrix entry that installs pnpm 11 and runs `pnpm install --frozen-lockfile`. Ensure the check runs for pull requests so restoring the overrides to an unsupported location would fail before merge.
ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools
PR Summary by QodoMove pnpm overrides to workspace configuration
AI Description
Diagram
High-Level Assessment
Files changed (2)
|
Problem
The recent dependency sweep added
pnpm.overridestopackage.json(to clear the js-yaml / brace-expansion advisories) and regenerated the lockfile with pnpm 10.pnpm 11 no longer reads the
pnpmfield frompackage.json. It warns:CI's publish job runs pnpm 11, so it sees no overrides while the lockfile records them, and the frozen install aborts:
The publish job dies in its "Bump version (patch)" step, so this plugin cannot release at all until this is fixed. The dependency fix itself was right; only its location was wrong.
Fix
pnpmkey frompackage.json.pnpm-workspace.yaml, where pnpm 11 reads them, with a comment explaining why the selectors are scoped to a major line and why they can't live inpackage.jsonany more.Verification
pnpm-lock.yamlis byte-for-byte unchanged — stilllockfileVersion: '9.0', so the lint job (pinned to pnpm 10) keeps working.npx -y pnpm@11 i --frozen-lockfile→ succeedspnpm i --frozen-lockfilewith pnpm 10 → succeedsjs-yaml@4.3.2andbrace-expansion@1.1.21,brace-expansion@5.0.12(nojs-yaml@4.1.1, nobrace-expansion@1.1.14).pnpm run lint→ 0 errors.🤖 Generated with Claude Code
https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw