chore: match Renovate's minimum release age to pnpm's - #356
Merged
Merged
Conversation
pnpm 11+ refuses to install versions published less than a day ago, but Renovate can propose them sooner, so its PRs fail at install until the release ages. State the one-day window explicitly in pnpm-workspace.yaml, give the grouped npm Renovate rule the same window, and exempt playcanvas in pnpm so engine updates still install as soon as they are released.
|
commit: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Since #349 moved the repo to pnpm 12,
pnpm installrefuses lockfile entries published less than a day ago (minimumReleaseAge, which defaults to 1440 minutes from pnpm 11). Renovate doesn't know about that window, so it can open or update a PR with a release pnpm won't install yet. That is why every check on #348 currently fails at install withERR_PNPM_MINIMUM_RELEASE_AGE_VIOLATION:vitest5.0.2 and three@vitest/*packages were published about five hours before Renovate pushed.The
playcanvasrule is hit hardest. It setsminimumReleaseAge: "0"andprCreation: "immediate", so every engine bump would fail install for its first day.Change
pnpm-workspace.yaml: stateminimumReleaseAge: 1440explicitly instead of relying on pnpm's default, and exemptplaycanvasthroughminimumReleaseAgeExcludeso engine updates still install as soon as they are released.renovate.json: give the grouped npm rule the same one-dayminimumReleaseAge, so Renovate only proposes versions pnpm will install. The laterplaycanvasrule still overrides it with"0", and its new description points at the pnpm exemption.Verification
pnpm install --frozen-lockfilepasses the supply-chain check with the new settings. The lockfile is unchanged.minimumReleaseAgeto 381 days, past the age of the lockedplaycanvas@2.11.8. With no exclusion, 275 entries failed. Excluding a non-existent package still gave 275. Excludingplaycanvasgave 274.renovate-config-validator --strict(Renovate 44.111.0) acceptsrenovate.json.#348 itself needs no changes. Locally, with
vitestand@vitest/coverage-v8on 5.0.1 (old enough for the policy) and everything else from Renovate's branch, build, format, lint and tests matchmain. Re-running its checks oncevitest5.0.2 is a day old (after 09:00 UTC on 2026-09-26) should get it past install.No changeset: this only changes repository config.