Skip to content

fix(deps): move pnpm settings out of package.json into pnpm-workspace.yaml - #631

Merged
phil-davis merged 1 commit into
masterfrom
fix/pnpm-settings-workspace
Sep 16, 2026
Merged

phil-davis merged 1 commit into
masterfrom
fix/pnpm-settings-workspace

Conversation

@oc-tmueller

Copy link
Copy Markdown
Contributor

The failure

The JS Unit job on #628 dies at make test-js before a single spec runs:

npx --yes pnpm@10 install --frozen-lockfile && touch node_modules
 ERR_PNPM_LOCKFILE_CONFIG_MISMATCH  Cannot proceed with the frozen installation.
 The current "overrides" configuration doesn't match the value found in the lockfile
make: *** [Makefile:95: node_modules] Error 1

Dependabot's regenerated pnpm-lock.yaml has no overrides: block, while package.json still declares 21 overrides.

Root cause

pnpm >= 11 no longer reads the pnpm field in package.json — those settings moved to pnpm-workspace.yaml:

[WARN] The "pnpm" field in package.json is no longer read by pnpm.
       The following keys were ignored: "pnpm.peerDependencyRules", "pnpm.overrides".

Dependabot has moved to such a pnpm; the Makefile pins pnpm@10, which does still read the field. The two disagree about the effective configuration, so Dependabot resolves without the overrides and the frozen install rejects the result.

Reproduced by re-running the resolution locally against dependabot/npm_and_yarn/minor-and-patch-96b5e73bd6:

resolution overrides: in lock vs. Dependabot's lock on #628
pnpm@10 install --lockfile-only present 225 / -378 lines different
pnpm@11 install --lockfile-only absent byte-identical
pnpm@12 install --lockfile-only absent byte-identical

So this is not a one-off bad Dependabot run — it will break every future Dependabot pull request here. The uglier half is invisible in CI: under pnpm >= 11 the 21 transitive pins added in #605 to close the Dependabot alerts do not apply at all. Today only minimatch and picomatch actually resolve elsewhere, and to newer versions rather than vulnerable ones, but the floor those pins are supposed to provide is gone.

The change

Move pnpm.overrides and pnpm.peerDependencyRules into pnpm-workspace.yaml, which pnpm 10, 11 and 12 all read. Nothing else changes — in particular pnpm-lock.yaml is untouched, because the existing lockfile is already correct for this configuration.

Verification

  • pnpm@10 install --frozen-lockfile (the exact command from Makefile:95) passes, with pnpm-lock.yaml left unmodified.
  • pnpm 12 on the unchanged lockfile: Lockfile is up to date, resolution step is skipped.
  • pnpm 10, 11 and 12 each regenerate a byte-identical lockfile from this configuration, so Dependabot and CI will stop fighting over it.
  • The move is resolution-neutral: regenerating the lockfile with pnpm@10 before and after the move yields identical files.
  • pnpm vite build reproduces the committed bundle unchanged.

tests/js/karma.config.cjs needs a surrounding core checkout, so the specs themselves were not run locally — but the failure is entirely in the install step and the resolved tree is unchanged, so CI on this PR exercises the real thing.

Follow-ups

….yaml

pnpm >= 11 no longer reads the "pnpm" field in package.json, so both the
overrides and the peerDependencyRules were silently ignored there:

  [WARN] The "pnpm" field in package.json is no longer read by pnpm.
         The following keys were ignored: "pnpm.peerDependencyRules",
         "pnpm.overrides".

Dependabot has moved to such a pnpm, while the Makefile pins pnpm@10, which
does still read the field. The two therefore disagree about the effective
configuration: Dependabot regenerates pnpm-lock.yaml without the `overrides:`
block, and the following `pnpm install --frozen-lockfile` in `make test-js`
aborts with

  ERR_PNPM_LOCKFILE_CONFIG_MISMATCH  Cannot proceed with the frozen
  installation. The current "overrides" configuration doesn't match the value
  found in the lockfile

That broke the JS Unit job on #628 and would break every future Dependabot
pull request. The more consequential half is invisible: under pnpm >= 11 the
21 transitive pins added in #605 to close the Dependabot alerts do not apply
at all.

pnpm-workspace.yaml is read by pnpm 10, 11 and 12 alike. Verified that all
three then resolve to a byte-identical lockfile, that the existing lockfile
stays valid unchanged (`pnpm install --frozen-lockfile` passes, and pnpm 12
reports "Lockfile is up to date, resolution step is skipped"), and that
`pnpm vite build` produces the same bundle. The move changes no resolution:
regenerating the lockfile before and after yields identical files.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Thomas Müller <323649642+oc-tmueller@users.noreply.github.com>
@phil-davis
phil-davis merged commit a984816 into master Sep 16, 2026
14 checks passed
@phil-davis
phil-davis deleted the fix/pnpm-settings-workspace branch September 16, 2026 10:38
oc-tmueller added a commit that referenced this pull request Sep 23, 2026
chore: bump version to 4.3.1

Release for the ownCloud 11.0.1 line. The notable change is that no released
version of this app carries the return-URL validation yet: v4.3.0 was tagged
2026-07-20 at #613 and #620 landed after it.

Also in: the pnpm settings move and lockfile regeneration (#624, #631), the
JavaScript unit test harness (#623), the appstore make target removal (#634),
the signed release and distribution-scan workflows (#616, #617), the community
health files (#601), translations (#618) and dependency bumps (#615, #626,
#628, #636).

The changelog gains two backfilled sections while we are here. 4.3.0 shipped
with no entry at all - its content is summarised from the 48 commits between
v4.2.2 and v4.3.0 rather than enumerated - and 4.2.3 was only ever recorded on
the 4.2 branch, so master's history skipped it.

Signed-off-by: Thomas Müller <323649642+oc-tmueller@users.noreply.github.com>
Co-authored-by: Thomas Müller <323649642+oc-tmueller@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants