F283: Move diffhub from npm to pnpm - #63
Conversation
Replace package-lock.json with pnpm-lock.yaml, pin packageManager to pnpm@12.8.1, and move root workspaces to pnpm-workspace.yaml. Switch CI (ci.yml, npm-publish.yml), lefthook, the cmux dock/config, and AGENTS.md/README docs from npm to pnpm equivalents. Workspace deps on @diffhub/diff-core move from "*" to "workspace:*", which pnpm requires to link the local package instead of looking it up on the registry. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015w5CFjfYYWSrnPexV8xYnv
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015w5CFjfYYWSrnPexV8xYnv
|
The latest updates on your projects. Learn more about Vercel for GitHub. 1 Skipped Deployment
|
|
Verdict: pass. 1 covered, 1 skipped, 0 failed. CI green at 95062f5 (pnpm install/lint/check-types/test/build); real-app serve (pnpm --filter diffhub run prepack + node bin/diffhub.mjs serve) returned a correct /api/files diff.
Stamp: Residual risk not exercised by this PR: the OIDC trusted-publish step in This PR also touches CI config ( |
pnpm doesn't hoist a devDependency declared only in apps/cli up to the workspace root the way npm did, so `pnpm exec changeset status` from root failed CI with "Command changeset not found". Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015w5CFjfYYWSrnPexV8xYnv
There was a problem hiding this comment.
What this PR does
This PR switches DiffHub’s development, automated checks and release process from npm to pnpm. It updates workspace dependencies and contributor commands; the diff viewer’s features stay the same.
Factory review (codex): no blocking issues found.
-
.factory/plans/F283.md:5(taste-lint) Straight quotes in rendered copy (2 hits: .factory/plans/F283.md:5, .factory/plans/F283.md:6) -
.factory/plans/F283.md:5(taste-lint) Sentence over 25 words joins several clauses
Switches this monorepo's own build tooling from npm to pnpm:
packageManagerpinned topnpm@12.8.1,workspacesmoved frompackage.jsontopnpm-workspace.yaml,package-lock.jsonreplaced bypnpm-lock.yaml, and everynpm run/npm install/npm ci/npxin CI (ci.yml,npm-publish.yml), lefthook, the cmux dock/config,vercel.json, and the AGENTS.md docs switched to the pnpm equivalent.@diffhub/diff-core's workspace dependency moved from"*"to"workspace:*", which pnpm needs to link it locally instead of looking it up on the npm registry.Left the marketing copy that tells end users to run
npx diffhub@latestornpm install -g diffhubuntouched — that installs the published package from the npm registry, which this migration doesn't change. Decisions and the full list of touched files are in.factory/plans/F283.md.Verified locally:
pnpm install,pnpm run lint,pnpm run check-types,pnpm run test, andpnpm run buildall pass, andpnpm --filter diffhub run prepackfollowed bynode apps/cli/bin/diffhub.mjs serveserved the real app and returned a correct/api/filesdiff.Learned: pnpm 12 doesn't auto-link a workspace dependency pinned to a bare
"*"range the way npm workspaces do — it tried to fetch@diffhub/diff-corefrom the registry and 404'd until I switched it toworkspace:*. Also, pnpm 12's schema for allow-listing postinstall scripts isallowBuilds(a map), not theonlyBuiltDependenciesarray from older pnpm docs;pnpm approve-builds --allrewrote my guess to the current shape. The one thing this PR doesn't exercise for real: the OIDC trusted-publish step innpm-publish.yml, since I dropped npm's OIDC-upgrade step in favor of pnpm 12's own trusted-publishing support without a live registry publish to confirm it.Signal
none: internal tooling change (package manager for this repo's own build/CI), not a user-visible product change.