Skip to content

chore: upgrade pnpm to v12 - #349

Merged
willeastcott merged 1 commit into
mainfrom
chore/pnpm-12
Sep 24, 2026
Merged

willeastcott merged 1 commit into
mainfrom
chore/pnpm-12

Conversation

@willeastcott

Copy link
Copy Markdown
Contributor

Summary

Renovate's grouped major PR #348 fails at pnpm install under pnpm 12, so none of its other updates get built or tested. This lands pnpm 12 on its own first. Once it's on main, Renovate should rebase #348 without pnpm, and its CI will run for the remaining updates.

Changes

  • packageManager is now pnpm@12.6.0. pnpm 11+ records itself in pnpm-lock.yaml as a new header document (pnpm and its per-platform binaries; the hashes match the npm registry). The rest of the lockfile is unchanged.
  • allowBuilds in pnpm-workspace.yaml denies the install scripts of canvas, esbuild, msw and unrs-resolver. pnpm 10 skipped these with a warning; pnpm 11 made strictDepBuilds the default, so they now fail the install unless listed. false keeps today's behaviour: none of them has ever run here, and none is a direct dependency.
  • Release workflow: removed NPM_CONFIG_PROVENANCE: true from changesets.yml. pnpm 11+ publishes without the npm CLI and no longer reads npm_config_* variables, so the setting was ignored. Provenance should still be attached: under OIDC trusted publishing, pnpm enables it automatically when the repo and package are public, matching the npm CLI (see pnpm/crates/publish/src/oidc/provenance.rs at v12.6.0).

Verification (local, pnpm 12.6.0)

  • pnpm run build, pnpm run lint, pnpm test and the Prettier check pass with the same results as on main. pnpm install --frozen-lockfile with CI=true passes.
  • The built dist of both packages is byte-identical to a pnpm 10 build of main.
  • pnpm pack output matches pnpm 10's file for file. The only difference is key order in blocks' package.json, where workspace:* is still rewritten to 0.11.5.
  • A dry run of the pnpm publish --json --access public --tag latest --no-git-checks command that changeset publish runs succeeds. pnpm -w changeset runs, and pnpm store path --silent (used by setup-node's pnpm cache) works.
  • corepack 0.35 runs pnpm 12; it downloads the native binary itself.

After the first release

PR CI can't exercise a real publish. After the first release under pnpm 12, check that npm shows provenance for both packages and that the git tags and GitHub releases were created.

No changeset: the published packages don't change.

🤖 Generated with Claude Code

Renovate's grouped major PR (#348) can't install under pnpm 12, which
hides every other update in it. Land pnpm on its own first.

- Bump packageManager to pnpm@12.6.0. pnpm 11+ records itself in
  pnpm-lock.yaml as a new header document (pnpm and its per-platform
  binaries); the rest of the lockfile is unchanged.
- pnpm 11 made strictDepBuilds the default, so the install scripts pnpm
  10 skipped with a warning (canvas, esbuild, msw, unrs-resolver) now
  fail the install. Deny them explicitly in allowBuilds, which keeps
  today's behaviour: none of them has ever run here.
- Drop NPM_CONFIG_PROVENANCE from the release workflow. pnpm 11+
  publishes without the npm CLI and no longer reads npm_config_*
  variables, so the setting is ignored. Provenance is still attached:
  under OIDC trusted publishing, pnpm enables it automatically for a
  public repo and package, as the npm CLI does.

Verified locally with pnpm 12.6.0: build, lint, test and fmt pass. The
built dist and packed tarballs for both packages match pnpm 10's (only
key order differs in blocks' package.json, where workspace:* is still
rewritten to 0.11.5), and a dry run of the pnpm publish command that
changesets runs succeeds.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@changeset-bot

changeset-bot Bot commented Sep 24, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 54d3d81

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@pkg-pr-new

pkg-pr-new Bot commented Sep 24, 2026

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/@playcanvas/blocks@349
npm i https://pkg.pr.new/@playcanvas/react@349

commit: 54d3d81

@willeastcott willeastcott self-assigned this Sep 24, 2026
@willeastcott
willeastcott merged commit b0351f1 into main Sep 24, 2026
7 checks passed
@willeastcott
willeastcott deleted the chore/pnpm-12 branch September 24, 2026 17:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant