From 5851a55855d1ca11c1535b8eb3a341a0e04883f1 Mon Sep 17 00:00:00 2001 From: Cameron Daniel Date: Wed, 27 May 2026 15:44:15 +0200 Subject: [PATCH 1/3] move pnpm onlyBuiltDependencies to pnpm-workspace.yaml MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit pnpm 10 stopped reading settings from the "pnpm" field in package.json — the previous fix was silently ignored with a warning. Settings now live in pnpm-workspace.yaml. Also run pnpm install in the Test job so this class of regression fails on every push/PR instead of only on tag pushes. --- .github/workflows/ci.yml | 14 ++++++++++++++ elo-tauri/package.json | 3 --- elo-tauri/pnpm-workspace.yaml | 2 ++ 3 files changed, 16 insertions(+), 3 deletions(-) create mode 100644 elo-tauri/pnpm-workspace.yaml diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 2e19d0b..9e50a9d 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -64,6 +64,20 @@ jobs: - uses: Swatinem/rust-cache@v2 + - name: Setup Node.js + uses: actions/setup-node@v6 + with: + node-version: 22 + + - name: Install pnpm + uses: pnpm/action-setup@v5 + with: + version: latest + + - name: Install frontend deps + working-directory: elo-tauri + run: pnpm install --frozen-lockfile + - name: Run tests run: cargo test --workspace diff --git a/elo-tauri/package.json b/elo-tauri/package.json index 8bada9b..59efb88 100644 --- a/elo-tauri/package.json +++ b/elo-tauri/package.json @@ -20,8 +20,5 @@ "@tauri-apps/cli": "^2", "vite": "^6.0.3", "typescript": "~5.6.2" - }, - "pnpm": { - "onlyBuiltDependencies": ["esbuild"] } } diff --git a/elo-tauri/pnpm-workspace.yaml b/elo-tauri/pnpm-workspace.yaml new file mode 100644 index 0000000..efc037a --- /dev/null +++ b/elo-tauri/pnpm-workspace.yaml @@ -0,0 +1,2 @@ +onlyBuiltDependencies: + - esbuild From 19d4e73f268e12641be1363303e2e387aa438653 Mon Sep 17 00:00:00 2001 From: Cameron Daniel Date: Wed, 27 May 2026 15:50:23 +0200 Subject: [PATCH 2/3] pin pnpm to v9 to avoid strict built-deps behavior MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit pnpm 10 added strict rejection of dependencies with unallowlisted build scripts (esbuild's postinstall trips it). The allowlist setting then moved twice — out of package.json 'pnpm' field (10) and into pnpm-workspace.yaml (11), but the workspace file isn't being honored in our single-package layout. Pin to pnpm 9 until the config story settles. Drops the unused elo-tauri/pnpm-workspace.yaml. --- .github/workflows/ci.yml | 18 +++++++++++++++--- elo-tauri/pnpm-workspace.yaml | 2 -- 2 files changed, 15 insertions(+), 5 deletions(-) delete mode 100644 elo-tauri/pnpm-workspace.yaml diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 9e50a9d..315bf2a 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -72,7 +72,11 @@ jobs: - name: Install pnpm uses: pnpm/action-setup@v5 with: - version: latest + # Pinned: pnpm 10+ rejects ignored build scripts (esbuild postinstall). + # Settings location for the allowlist has shifted between 10 and 11 + # (package.json "pnpm" field deprecated, pnpm-workspace.yaml not + # honored in our layout). Stay on 9 until that stabilizes. + version: 9 - name: Install frontend deps working-directory: elo-tauri @@ -104,7 +108,11 @@ jobs: - name: Install pnpm uses: pnpm/action-setup@v5 with: - version: latest + # Pinned: pnpm 10+ rejects ignored build scripts (esbuild postinstall). + # Settings location for the allowlist has shifted between 10 and 11 + # (package.json "pnpm" field deprecated, pnpm-workspace.yaml not + # honored in our layout). Stay on 9 until that stabilizes. + version: 9 - name: Install Tauri CLI run: cargo install tauri-cli --version "^2" @@ -151,7 +159,11 @@ jobs: - name: Install pnpm uses: pnpm/action-setup@v5 with: - version: latest + # Pinned: pnpm 10+ rejects ignored build scripts (esbuild postinstall). + # Settings location for the allowlist has shifted between 10 and 11 + # (package.json "pnpm" field deprecated, pnpm-workspace.yaml not + # honored in our layout). Stay on 9 until that stabilizes. + version: 9 - name: Install Tauri CLI run: cargo install tauri-cli --version "^2" diff --git a/elo-tauri/pnpm-workspace.yaml b/elo-tauri/pnpm-workspace.yaml deleted file mode 100644 index efc037a..0000000 --- a/elo-tauri/pnpm-workspace.yaml +++ /dev/null @@ -1,2 +0,0 @@ -onlyBuiltDependencies: - - esbuild From 6cef292c10e7f240fb6b513412dc33cdee6c57f4 Mon Sep 17 00:00:00 2001 From: Cameron Daniel Date: Wed, 27 May 2026 15:52:20 +0200 Subject: [PATCH 3/3] bump pnpm/action-setup v5 -> v6, action-gh-release v2 -> v3 Other actions already on their latest major: actions/checkout@v6 actions/setup-node@v6 actions/upload-artifact@v7 actions/download-artifact@v8 Swatinem/rust-cache@v2 dtolnay/rust-toolchain@nightly (channel pin, not a version) --- .github/workflows/ci.yml | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 315bf2a..0c66b29 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -70,7 +70,7 @@ jobs: node-version: 22 - name: Install pnpm - uses: pnpm/action-setup@v5 + uses: pnpm/action-setup@v6 with: # Pinned: pnpm 10+ rejects ignored build scripts (esbuild postinstall). # Settings location for the allowlist has shifted between 10 and 11 @@ -106,7 +106,7 @@ jobs: node-version: 22 - name: Install pnpm - uses: pnpm/action-setup@v5 + uses: pnpm/action-setup@v6 with: # Pinned: pnpm 10+ rejects ignored build scripts (esbuild postinstall). # Settings location for the allowlist has shifted between 10 and 11 @@ -157,7 +157,7 @@ jobs: node-version: 22 - name: Install pnpm - uses: pnpm/action-setup@v5 + uses: pnpm/action-setup@v6 with: # Pinned: pnpm 10+ rejects ignored build scripts (esbuild postinstall). # Settings location for the allowlist has shifted between 10 and 11 @@ -207,7 +207,7 @@ jobs: ls -la release-assets/ - name: Create GitHub Release - uses: softprops/action-gh-release@v2 + uses: softprops/action-gh-release@v3 with: generate_release_notes: true files: release-assets/*