chore: upgrade pnpm to v12 - #349
Merged
Merged
Conversation
Renovate's grouped major PR (#348) can't install under pnpm 12, which hides every other update in it. Land pnpm on its own first. - Bump packageManager to pnpm@12.6.0. pnpm 11+ records itself in pnpm-lock.yaml as a new header document (pnpm and its per-platform binaries); the rest of the lockfile is unchanged. - pnpm 11 made strictDepBuilds the default, so the install scripts pnpm 10 skipped with a warning (canvas, esbuild, msw, unrs-resolver) now fail the install. Deny them explicitly in allowBuilds, which keeps today's behaviour: none of them has ever run here. - Drop NPM_CONFIG_PROVENANCE from the release workflow. pnpm 11+ publishes without the npm CLI and no longer reads npm_config_* variables, so the setting is ignored. Provenance is still attached: under OIDC trusted publishing, pnpm enables it automatically for a public repo and package, as the npm CLI does. Verified locally with pnpm 12.6.0: build, lint, test and fmt pass. The built dist and packed tarballs for both packages match pnpm 10's (only key order differs in blocks' package.json, where workspace:* is still rewritten to 0.11.5), and a dry run of the pnpm publish command that changesets runs succeeds. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
commit: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Renovate's grouped major PR #348 fails at
pnpm installunder pnpm 12, so none of its other updates get built or tested. This lands pnpm 12 on its own first. Once it's on main, Renovate should rebase #348 without pnpm, and its CI will run for the remaining updates.Changes
packageManageris nowpnpm@12.6.0. pnpm 11+ records itself inpnpm-lock.yamlas a new header document (pnpm and its per-platform binaries; the hashes match the npm registry). The rest of the lockfile is unchanged.allowBuildsinpnpm-workspace.yamldenies the install scripts ofcanvas,esbuild,mswandunrs-resolver. pnpm 10 skipped these with a warning; pnpm 11 madestrictDepBuildsthe default, so they now fail the install unless listed.falsekeeps today's behaviour: none of them has ever run here, and none is a direct dependency.NPM_CONFIG_PROVENANCE: truefromchangesets.yml. pnpm 11+ publishes without the npm CLI and no longer readsnpm_config_*variables, so the setting was ignored. Provenance should still be attached: under OIDC trusted publishing, pnpm enables it automatically when the repo and package are public, matching the npm CLI (seepnpm/crates/publish/src/oidc/provenance.rsat v12.6.0).Verification (local, pnpm 12.6.0)
pnpm run build,pnpm run lint,pnpm testand the Prettier check pass with the same results as on main.pnpm install --frozen-lockfilewithCI=truepasses.distof both packages is byte-identical to a pnpm 10 build of main.pnpm packoutput matches pnpm 10's file for file. The only difference is key order in blocks'package.json, whereworkspace:*is still rewritten to0.11.5.pnpm publish --json --access public --tag latest --no-git-checkscommand thatchangeset publishruns succeeds.pnpm -w changesetruns, andpnpm store path --silent(used bysetup-node's pnpm cache) works.After the first release
PR CI can't exercise a real publish. After the first release under pnpm 12, check that npm shows provenance for both packages and that the git tags and GitHub releases were created.
No changeset: the published packages don't change.
🤖 Generated with Claude Code