chore: swap pnpm resolutionMode time-based for minimumReleaseAge - #4984
Merged
Merged
Conversation
time-based does not only prefer publish-time-current subdependencies, it also resolves every direct dependency to the floor of its range. The setting was inert in .npmrc and first went live with #4977, so the first full re-resolution after that -- lock file maintenance #4983 -- came back as a mass downgrade: nx 14.0.0 from 2022 (floor of the config-nx-scopes `nx: >=14.0.0` peer range), vitepress 1.3.4, @types/node 22.0.0, lerna 10.0.0, vite 8.0.0. Those downgrades pulled in @parcel/watcher and vue-demi, whose install scripts are not listed in allowBuilds, so strictDepBuilds failed the install with ERR_PNPM_IGNORED_BUILDS. The build error was the symptom; the downgrade was the event. minimumReleaseAge delivers the stated intent -- never install a release that is only hours old -- without touching version selection. 2880 minutes (2 days) sits below renovate.minimumReleaseAge (3 days) so pnpm cannot reject a version Renovate has proposed. Verified locally with pnpm 11.24.0: `pnpm install --frozen-lockfile` passes the policy check over all lockfile entries, and an inflated cutoff rejects the lockfile, so the option is genuinely enforced rather than silently ignored. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017hoRjc4XLWFeN3yJbjUxe4
Confidence Score: 5/5The PR appears safe to merge, with no concrete blocking or independently actionable non-blocking issue identified. The configured pnpm version supports the new workspace setting, documented installation paths use that supported version, and the current frozen lockfile has been verified against the intended two-day policy.
|
| Filename | Overview |
|---|---|
| pnpm-workspace.yaml | Replaces downgrade-prone time-based dependency resolution with a supported two-day release-age gate and accurately documents the resulting install policy. |
Reviews (1): Last reviewed commit: "chore: swap pnpm resolutionMode time-bas..." | Re-trigger Greptile
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Replaces
resolutionMode: time-basedwithminimumReleaseAge: 2880inpnpm-workspace.yaml, and documents whyresolutionModestays at the default.Why
time-baseddoes more than its comment in #4977 claimed. It does not only prefer publish-time-current subdependencies — it also resolves every direct dependency to the floor of its range.The setting was inert while it lived in
.npmrc(pnpm 11 ignores pnpm settings there, silently), so this only became visible once #4977 moved it intopnpm-workspace.yaml. The first full re-resolution after that — lock file maintenance #4983 — came back as a mass downgrade, +2971/−923:config-nx-scopes,>=14.0.0)Those downgrades pulled in two packages master does not have at all —
@parcel/watcher@2.0.4(via nx 14) andvue-demi@0.14.10(via@vueuse/core11, from vitepress 1.3.4). Both run install scripts, neither is listed inallowBuilds, sostrictDepBuildsfailed CI withERR_PNPM_IGNORED_BUILDS. The build error was the symptom; the downgrade was the event.Why
minimumReleaseAgeIt delivers the stated intent of the original setting — never install a release that is only hours old, limiting exposure to a freshly compromised version — without touching version selection at all.
renovate.minimumReleaseAge("3 days"inpackage.json), so pnpm can never reject a version Renovate has proposed. Lock file maintenance is exempt from Renovate's gate, and that is exactly where pnpm's own gate now does the work.minimumReleaseAgeStrict, so the existing lockfile is verified against the policy on every install, not just new resolutions. A hand-edited lockfile can no longer smuggle in a fresh release. A genuinely urgent same-day bump needspnpm install --config.minimumReleaseAge=0.Verification
Local, pnpm 11.24.0:
pnpm install --frozen-lockfile→✓ Lockfile passes supply-chain policies (954 entries in 3.5s), lockfile unchanged, no ignored-builds failure.pnpm install --frozen-lockfile --config.minimumReleaseAge=5256000→ fails with per-package rejections, which proves the key is genuinely enforced rather than silently ignored — the trap.npmrcfell into.Notes
pnpm-lock.yamlis intentionally untouched. It still carries the staletime:block thattime-basedwrote; pnpm only emits that block in that mode, so the next full re-resolution drops it.🤖 Generated with Claude Code
https://claude.ai/code/session_017hoRjc4XLWFeN3yJbjUxe4