Repository navigation
ecto - chore: upgrade pnpm - #419
Conversation
Pin packageManager to pnpm 12.5.1 with the corepack integrity hash. Co-authored-by: Jared Wray <me@jaredwray.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #419 +/- ##
=========================================
Coverage 100.00% 100.00%
=========================================
Files 9 9
Lines 406 406
Branches 94 94
=========================================
Hits 406 406 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: bef01ed4c0
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| '@pnpm/exe.win32-arm64': 12.5.1 | ||
| '@pnpm/exe.win32-x64': 12.5.1 | ||
|
|
||
| --- |
There was a problem hiding this comment.
Restore a single YAML document in the lockfile
The added --- starts a second YAML document instead of merging the pnpm entries into the existing lockfile. pnpm's lockfile reader expects exactly one document and reports a broken lockfile (expected a single document in the stream, but found more), so the pnpm install --frozen-lockfile step in tests.yml, code-coverage.yml, release.yaml, and the cloud setup script cannot install dependencies.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
The second --- at pnpm-lock.yaml:158 is what pnpm 12.5.1 writes when it records packageManagerDependencies. Restoring the pre-change lockfile and running pnpm install produces the same two-document file, and pnpm install --frozen-lockfile succeeds with pnpm 12.5.1 (locally, and in CI on this PR). The expected a single document in the stream, but found more error is in the pnpm 11.22.0 reader this pin replaces; it is not in the 12.5.1 package. Merging the documents by hand does not stick, because the next install writes the separator back.
Please check if the PR fulfills these requirements
What kind of change does this PR introduce?
Dependency maintenance — the dev phase (package manager tooling).
Summary
Pin
packageManagertopnpm@12.5.1with the integrity hash fromcorepack use. pnpm is not a devDependency, so the target is the newest stable release published at least 7 days ago (12.6.0and11.27.1are younger than that gate). The field previously namedpnpm@11.22.0with no hash.Changes
packageManagerpnpm@11.22.0→pnpm@12.5.1+sha512.…DEFENSE_IN_DEPTH.mdverified pin updated to matchArtifact diffs
Verification
corepack use pnpm@12.5.1wrote the hashpnpm install --frozen-lockfileclean on 12.5.1pnpm buildpasses (tsdown0.23.0) on Node 22.22.2pnpm testpasses — 239 tests, 100% coverage