fix(deps): move pnpm settings out of package.json into pnpm-workspace.yaml - #631
Merged
Merged
Conversation
….yaml
pnpm >= 11 no longer reads the "pnpm" field in package.json, so both the
overrides and the peerDependencyRules were silently ignored there:
[WARN] The "pnpm" field in package.json is no longer read by pnpm.
The following keys were ignored: "pnpm.peerDependencyRules",
"pnpm.overrides".
Dependabot has moved to such a pnpm, while the Makefile pins pnpm@10, which
does still read the field. The two therefore disagree about the effective
configuration: Dependabot regenerates pnpm-lock.yaml without the `overrides:`
block, and the following `pnpm install --frozen-lockfile` in `make test-js`
aborts with
ERR_PNPM_LOCKFILE_CONFIG_MISMATCH Cannot proceed with the frozen
installation. The current "overrides" configuration doesn't match the value
found in the lockfile
That broke the JS Unit job on #628 and would break every future Dependabot
pull request. The more consequential half is invisible: under pnpm >= 11 the
21 transitive pins added in #605 to close the Dependabot alerts do not apply
at all.
pnpm-workspace.yaml is read by pnpm 10, 11 and 12 alike. Verified that all
three then resolve to a byte-identical lockfile, that the existing lockfile
stays valid unchanged (`pnpm install --frozen-lockfile` passes, and pnpm 12
reports "Lockfile is up to date, resolution step is skipped"), and that
`pnpm vite build` produces the same bundle. The move changes no resolution:
regenerating the lockfile before and after yields identical files.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Thomas Müller <323649642+oc-tmueller@users.noreply.github.com>
phil-davis
approved these changes
Sep 16, 2026
This was referenced Sep 16, 2026
Merged
oc-tmueller
added a commit
that referenced
this pull request
Sep 23, 2026
chore: bump version to 4.3.1 Release for the ownCloud 11.0.1 line. The notable change is that no released version of this app carries the return-URL validation yet: v4.3.0 was tagged 2026-07-20 at #613 and #620 landed after it. Also in: the pnpm settings move and lockfile regeneration (#624, #631), the JavaScript unit test harness (#623), the appstore make target removal (#634), the signed release and distribution-scan workflows (#616, #617), the community health files (#601), translations (#618) and dependency bumps (#615, #626, #628, #636). The changelog gains two backfilled sections while we are here. 4.3.0 shipped with no entry at all - its content is summarised from the 48 commits between v4.2.2 and v4.3.0 rather than enumerated - and 4.2.3 was only ever recorded on the 4.2 branch, so master's history skipped it. Signed-off-by: Thomas Müller <323649642+oc-tmueller@users.noreply.github.com> Co-authored-by: Thomas Müller <323649642+oc-tmueller@users.noreply.github.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The failure
The JS Unit job on #628 dies at
make test-jsbefore a single spec runs:Dependabot's regenerated
pnpm-lock.yamlhas nooverrides:block, whilepackage.jsonstill declares 21 overrides.Root cause
pnpm >= 11 no longer reads the
pnpmfield inpackage.json— those settings moved topnpm-workspace.yaml:Dependabot has moved to such a pnpm; the
Makefilepinspnpm@10, which does still read the field. The two disagree about the effective configuration, so Dependabot resolves without the overrides and the frozen install rejects the result.Reproduced by re-running the resolution locally against
dependabot/npm_and_yarn/minor-and-patch-96b5e73bd6:overrides:in lockpnpm@10 install --lockfile-onlypnpm@11 install --lockfile-onlypnpm@12 install --lockfile-onlySo this is not a one-off bad Dependabot run — it will break every future Dependabot pull request here. The uglier half is invisible in CI: under pnpm >= 11 the 21 transitive pins added in #605 to close the Dependabot alerts do not apply at all. Today only
minimatchandpicomatchactually resolve elsewhere, and to newer versions rather than vulnerable ones, but the floor those pins are supposed to provide is gone.The change
Move
pnpm.overridesandpnpm.peerDependencyRulesintopnpm-workspace.yaml, which pnpm 10, 11 and 12 all read. Nothing else changes — in particularpnpm-lock.yamlis untouched, because the existing lockfile is already correct for this configuration.Verification
pnpm@10 install --frozen-lockfile(the exact command fromMakefile:95) passes, withpnpm-lock.yamlleft unmodified.Lockfile is up to date, resolution step is skipped.pnpm vite buildreproduces the committed bundle unchanged.tests/js/karma.config.cjsneeds a surrounding core checkout, so the specs themselves were not run locally — but the failure is entirely in the install step and the resolved tree is unchanged, so CI on this PR exercises the real thing.Follow-ups
@dependabot recreateonce this lands, so it regenerates its lockfile with the overrides in place.4.2branch has the same config and already merged its equivalent bump (chore(deps-dev): bump vue from 3.5.40 to 3.5.42 in the minor-and-patch group #629) with the overrides stripped, since it has no JS Unit job to catch it. Its tip is broken today. Handled separately.ERR_PNPM_IGNORED_BUILDS: esbuild, and a full install (not a--lockfile-onlyone) writes anallowBuilds:stub intopnpm-workspace.yaml. Harmless while theMakefilepinspnpm@10; it will need an explicit build-script decision whenever that pin moves.