Skip to content

chore: swap pnpm resolutionMode time-based for minimumReleaseAge - #4984

Merged
escapedcat merged 1 commit into
masterfrom
chore/pnpm-minimum-release-age
Aug 31, 2026
Merged

escapedcat merged 1 commit into
masterfrom
chore/pnpm-minimum-release-age

Conversation

@escapedcat

Copy link
Copy Markdown
Member

What

Replaces resolutionMode: time-based with minimumReleaseAge: 2880 in pnpm-workspace.yaml, and documents why resolutionMode stays at the default.

Why

time-based does more than its comment in #4977 claimed. It does not only prefer publish-time-current subdependencies — it also resolves every direct dependency to the floor of its range.

The setting was inert while it lived in .npmrc (pnpm 11 ignores pnpm settings there, silently), so this only became visible once #4977 moved it into pnpm-workspace.yaml. The first full re-resolution after that — lock file maintenance #4983 — came back as a mass downgrade, +2971/−923:

package master #4983
nx (peer of config-nx-scopes, >=14.0.0) 23.1.1 14.0.0 (published 2022-04-21)
vitepress 1.6.4 1.3.4
@types/node 22.20.1 22.0.0
lerna 10.0.1 10.0.0
vite 8.2.2 8.0.0

Those downgrades pulled in two packages master does not have at all — @parcel/watcher@2.0.4 (via nx 14) and vue-demi@0.14.10 (via @vueuse/core 11, from vitepress 1.3.4). Both run install scripts, neither is listed in allowBuilds, so strictDepBuilds failed CI with ERR_PNPM_IGNORED_BUILDS. The build error was the symptom; the downgrade was the event.

Why minimumReleaseAge

It delivers the stated intent of the original setting — never install a release that is only hours old, limiting exposure to a freshly compromised version — without touching version selection at all.

  • The unit is minutes; 2880 = 2 days.
  • It deliberately sits below renovate.minimumReleaseAge ("3 days" in package.json), so pnpm can never reject a version Renovate has proposed. Lock file maintenance is exempt from Renovate's gate, and that is exactly where pnpm's own gate now does the work.
  • Setting it explicitly also enables minimumReleaseAgeStrict, so the existing lockfile is verified against the policy on every install, not just new resolutions. A hand-edited lockfile can no longer smuggle in a fresh release. A genuinely urgent same-day bump needs pnpm install --config.minimumReleaseAge=0.

Verification

Local, pnpm 11.24.0:

  • pnpm install --frozen-lockfile → ✓ Lockfile passes supply-chain policies (954 entries in 3.5s), lockfile unchanged, no ignored-builds failure.
  • pnpm install --frozen-lockfile --config.minimumReleaseAge=5256000 → fails with per-package rejections, which proves the key is genuinely enforced rather than silently ignored — the trap .npmrc fell into.

Notes

  • pnpm-lock.yaml is intentionally untouched. It still carries the stale time: block that time-based wrote; pnpm only emits that block in that mode, so the next full re-resolution drops it.
  • chore: lock file maintenance #4983 should be closed rather than merged. Renovate reopens lock file maintenance Monday before 5am, and that run will be a genuine refresh once this lands.

🤖 Generated with Claude Code

https://claude.ai/code/session_017hoRjc4XLWFeN3yJbjUxe4

time-based does not only prefer publish-time-current subdependencies, it also
resolves every direct dependency to the floor of its range. The setting was
inert in .npmrc and first went live with #4977, so the first full re-resolution
after that -- lock file maintenance #4983 -- came back as a mass downgrade:
nx 14.0.0 from 2022 (floor of the config-nx-scopes `nx: >=14.0.0` peer range),
vitepress 1.3.4, @types/node 22.0.0, lerna 10.0.0, vite 8.0.0.

Those downgrades pulled in @parcel/watcher and vue-demi, whose install scripts
are not listed in allowBuilds, so strictDepBuilds failed the install with
ERR_PNPM_IGNORED_BUILDS. The build error was the symptom; the downgrade was the
event.

minimumReleaseAge delivers the stated intent -- never install a release that is
only hours old -- without touching version selection. 2880 minutes (2 days)
sits below renovate.minimumReleaseAge (3 days) so pnpm cannot reject a version
Renovate has proposed.

Verified locally with pnpm 11.24.0: `pnpm install --frozen-lockfile` passes the
policy check over all lockfile entries, and an inflated cutoff rejects the
lockfile, so the option is genuinely enforced rather than silently ignored.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017hoRjc4XLWFeN3yJbjUxe4
@greptile-apps

greptile-apps Bot commented Aug 31, 2026

Copy link
Copy Markdown

Confidence Score: 5/5

The PR appears safe to merge, with no concrete blocking or independently actionable non-blocking issue identified.

The configured pnpm version supports the new workspace setting, documented installation paths use that supported version, and the current frozen lockfile has been verified against the intended two-day policy.

Important Files Changed

Filename Overview
pnpm-workspace.yaml Replaces downgrade-prone time-based dependency resolution with a supported two-day release-age gate and accurately documents the resulting install policy.

Reviews (1): Last reviewed commit: "chore: swap pnpm resolutionMode time-bas..." | Re-trigger Greptile

@escapedcat
escapedcat added this pull request to the merge queue Aug 31, 2026
Merged via the queue into master with commit 5638c5b Aug 31, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant