Skip to content

F283: Move diffhub from npm to pnpm - #63

Merged
mblode merged 4 commits into
mainfrom
f283-move-diffhub-from-npm-to-pnpm
Sep 30, 2026
Merged

mblode merged 4 commits into
mainfrom
f283-move-diffhub-from-npm-to-pnpm

Conversation

@mblode

@mblode mblode commented Sep 30, 2026 •

Copy link
Copy Markdown
Owner

Switches this monorepo's own build tooling from npm to pnpm: packageManager pinned to pnpm@12.8.1, workspaces moved from package.json to pnpm-workspace.yaml, package-lock.json replaced by pnpm-lock.yaml, and every npm run/npm install/npm ci/npx in CI (ci.yml, npm-publish.yml), lefthook, the cmux dock/config, vercel.json, and the AGENTS.md docs switched to the pnpm equivalent. @diffhub/diff-core's workspace dependency moved from "*" to "workspace:*", which pnpm needs to link it locally instead of looking it up on the npm registry.

Left the marketing copy that tells end users to run npx diffhub@latest or npm install -g diffhub untouched — that installs the published package from the npm registry, which this migration doesn't change. Decisions and the full list of touched files are in .factory/plans/F283.md.

Verified locally: pnpm install, pnpm run lint, pnpm run check-types, pnpm run test, and pnpm run build all pass, and pnpm --filter diffhub run prepack followed by node apps/cli/bin/diffhub.mjs serve served the real app and returned a correct /api/files diff.

Learned: pnpm 12 doesn't auto-link a workspace dependency pinned to a bare "*" range the way npm workspaces do — it tried to fetch @diffhub/diff-core from the registry and 404'd until I switched it to workspace:*. Also, pnpm 12's schema for allow-listing postinstall scripts is allowBuilds (a map), not the onlyBuiltDependencies array from older pnpm docs; pnpm approve-builds --all rewrote my guess to the current shape. The one thing this PR doesn't exercise for real: the OIDC trusted-publish step in npm-publish.yml, since I dropped npm's OIDC-upgrade step in favor of pnpm 12's own trusted-publishing support without a live registry publish to confirm it.

Signal

none: internal tooling change (package manager for this repo's own build/CI), not a user-visible product change.

mblode and others added 3 commits September 30, 2026 11:50
Replace package-lock.json with pnpm-lock.yaml, pin packageManager to
pnpm@12.8.1, and move root workspaces to pnpm-workspace.yaml. Switch
CI (ci.yml, npm-publish.yml), lefthook, the cmux dock/config, and
AGENTS.md/README docs from npm to pnpm equivalents. Workspace deps on
@diffhub/diff-core move from "*" to "workspace:*", which pnpm requires
to link the local package instead of looking it up on the registry.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015w5CFjfYYWSrnPexV8xYnv
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015w5CFjfYYWSrnPexV8xYnv
@vercel

vercel Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
diffhub-web Ignored Ignored Preview Sep 30, 2026 2:11am UTC

Request Review

@mblode
mblode marked this pull request as ready for review September 30, 2026 02:09
@mblode

mblode commented Sep 30, 2026 •

Copy link
Copy Markdown
Owner Author
Verdict: pass. 1 covered, 1 skipped, 0 failed. CI green at 95062f5 (pnpm install/lint/check-types/test/build); real-app serve (pnpm --filter diffhub run prepack + node bin/diffhub.mjs serve) returned a correct /api/files diff.

Stamp: node ~/.local/share/bots/stamp/runner.mjs --pr mblode/diffhub#63 returns skipped: over 1500 changed lines (exit 0, not an error — the diff is ~7,000 lines because it's dominated by the generated pnpm-lock.yaml). This is not the fetch failed transport error tracked in F275; it's a deterministic size-gate skip, so I'm not retrying it. Per the workflow's merge rule, a skipped review blocks merging regardless.

Residual risk not exercised by this PR: the OIDC trusted-publish step in npm-publish.yml now relies on pnpm 12's own trusted-publishing support (I dropped npm's OIDC-upgrade step) — no live registry publish confirmed it works.

This PR also touches CI config (.github/workflows/*) and instruction files (AGENTS.md), which puts it outside the auto-merge tier regardless of review state. Holding for Matt's explicit merge approval; not merging.

pnpm doesn't hoist a devDependency declared only in apps/cli up to
the workspace root the way npm did, so `pnpm exec changeset status`
from root failed CI with "Command changeset not found".

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015w5CFjfYYWSrnPexV8xYnv

@stamp-by-factory stamp-by-factory Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What this PR does

This PR switches DiffHub’s development, automated checks and release process from npm to pnpm. It updates workspace dependencies and contributor commands; the diff viewer’s features stay the same.

Factory review (codex): no blocking issues found.

  • .factory/plans/F283.md:5 (taste-lint) Straight quotes in rendered copy (2 hits: .factory/plans/F283.md:5, .factory/plans/F283.md:6)

  • .factory/plans/F283.md:5 (taste-lint) Sentence over 25 words joins several clauses

@mblode
mblode merged commit a641b90 into main Sep 30, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant