Skip to content

build: migrate from yarn to pnpm to harden the supply chain - #456

Merged
nanasess merged 2 commits into
masterfrom
feature/use-pnpm
Jun 1, 2026
Merged

nanasess merged 2 commits into
masterfrom
feature/use-pnpm

Conversation

@nanasess

@nanasess nanasess commented Jun 1, 2026 •

Copy link
Copy Markdown
Owner

Overview

Migrate the package manager from yarn 1 (classic) to pnpm 11 as a supply-chain hardening measure. This is not a plain swap: the main goal is to turn on pnpm's built-in defenses.

Why pnpm (supply-chain defenses)

Feature Protection
allowBuilds (install-time build scripts blocked by default) Arbitrary code execution from postinstall etc. becomes opt-in. Tampered packages can't run code on install.
minimumReleaseAge: 4320 (3-day cooldown) Freshly published versions are not adopted, dodging malicious releases pushed right after a maintainer-account takeover (most are detected/yanked within hours to a few days).
content-addressable store + integrity verification tarball hash verification
strict node_modules eliminates phantom deps; dependencies are limited to what is declared

unrs-resolver (jest's module resolver) runs from a prebuilt binary (@unrs/resolver-binding-*, an optional dep) and needs no native build, so it is explicitly denied via allowBuilds: { unrs-resolver: false }.

Note on minimumReleaseAgeExclude

pnpm's minimumReleaseAge is a verification gate, not a resolution filter: it does not automatically fall back to an older version, it rejects the install when the resolved tree contains a version that is too new. The browserslist data packages (baseline-browser-mapping, caniuse-lite, electron-to-chromium) publish almost daily, so a 3-day cooldown would make pnpm install --frozen-lockfile (used in CI) fail on every resolution. These packages are dev-only, data-only, and are never bundled into dist/ (they don't ship in the published action), so their supply-chain risk is negligible and they are excluded from the cooldown. The 3-day default still fully applies to everything that ships or runs install scripts.

Main changes

  • package.json: set packageManager to pnpm@11.5.0 (SHA512-pinned). Removed the non-functional husky setup (v4-style config block, no .husky directory) to cut a dependency.
  • pnpm-workspace.yaml (new): consolidates the supply-chain settings.
  • yarn.lock removed → pnpm-lock.yaml (new).
  • CI (test.yml / windows.yml): added pnpm/action-setup + actions/setup-node (cache: pnpm), both SHA-pinned, and switched yarn → pnpm.
  • dist/index.js: regenerated the ncc bundle because dependencies were re-resolved to the latest within their declared ranges (this is why the diff is large). lib/ is built from our own src and is unchanged.
  • Updated yarn references to pnpm in README / CLAUDE.md / test comments.

Verification

  • Ran pnpm install --frozen-lockfile / pnpm build / pnpm package / pnpm test locally: 97 passed.
  • Confirmed the lockfile passes the supply-chain policy check and that pnpm package regenerates the artifact deterministically.
  • Full CI matrix (test / windows) was green on the previous push; rerunning on this final 3-day config.

Rollback

node_modules is untracked, so reverting this PR restores the yarn setup completely.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores

    • パッケージマネージャーを Yarn から pnpm に変更しました
    • CI/CD ワークフローを pnpm ベースに更新しました
    • 開発設定(.gitignore など)とワークスペースのpnpm設定を追加・整備しました
    • 開発用依存やフック設定(例: husky)を整理しました
  • Documentation

    • 開発セットアップ、ビルド、パッケージ、テスト実行手順を pnpm 前提で更新しました
    • ドキュメント内のテスト実行例を pnpm に合わせて修正しました

@coderabbitai

coderabbitai Bot commented Jun 1, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@nanasess, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 6 minutes and 43 seconds. Learn how PR review limits work.

Your organization has run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 77a63752-b27f-4e02-9158-f9e142db93cc

📥 Commits

Reviewing files that changed from the base of the PR and between 8ec4112 and a717e46.

📒 Files selected for processing (2)
  • .github/workflows/test.yml
  • .github/workflows/windows.yml
📝 Walkthrough

ウォークスルー

このPRはプロジェクトを Yarn から pnpm に移行します。トップレベル設定と workspace ファイルを追加し、GitHub Actions ワークフローを pnpm 実行に置き換え、開発ドキュメントとテストコメントを pnpm ベースに更新します。

変更内容

Yarn から pnpm への統合移行

Layer / File(s) Summary
パッケージマネージャー設定と依存関係の更新
package.json, pnpm-workspace.yaml, .gitignore
トップレベル packageManager を pnpm@... に変更し、husky を削除。pnpm-workspace.yaml を追加して minimumReleaseAge: 4320、minimumReleaseAgeExclude と allowBuilds.unrs-resolver: false を設定し、.gitignore に .pnpm-store/ を追加。
CI/CDワークフロー: Yarn から pnpm へ
.github/workflows/test.yml, .github/workflows/windows.yml
test と test_default_version ジョブで pnpm/action-setup と actions/setup-node(cache: pnpm)を導入し、pnpm install --frozen-lockfile → pnpm build → pnpm package → pnpm test を実行するよう置換。
ドキュメント: 開発・実行手順を pnpm に統一
README.md, CLAUDE.md, __tests__/chromedriver-api.test.ts
開発セットアップ・実行手順と単一テスト実行コマンドを yarn から pnpm に更新し、README/CLAUDE の該当手順とテストファイル内コメントを pnpm ベースに統一。

🎯 3 (Moderate) | ⏱️ ~20 minutes

🐰 パッケージマネージャーの切り替え
Yarn から pnpm へ、ぴょんと移行
CI とドキュメントも一緒に
コマンドはすべて pnpm に統一
さあビルドしてテストを走らせよう 🥕

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed タイトルはこのPRの主要な変更内容—Yarnからpnpmへの移行とサプライチェーン強化—を明確かつ簡潔に要約しており、開発者の意図を正確に反映しています。
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feature/use-pnpm

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request migrates the project's package manager from Yarn to pnpm, updating the configuration files, documentation, and scripts accordingly, while also removing Husky. Feedback on the changes highlights that the supply-chain hardening configurations (such as minimum release age and build script blocks) are incorrectly placed in pnpm-workspace.yaml where they are ignored by pnpm. The reviewer recommends moving these settings to .npmrc and package.json respectively, deleting the invalid workspace file, and updating the corresponding documentation in CLAUDE.md.

Comment thread pnpm-workspace.yaml
Comment thread CLAUDE.md
パッケージマネージャを yarn 1 (classic) から pnpm 11 へ移行する。
単なる置換ではなく、pnpm のサプライチェーン防御機能を有効化する
ことが主目的:

- インストール時ビルドスクリプトを既定でブロック (allowBuilds)。
  unrs-resolver (jest のモジュール解決器) はプリビルドバイナリで
  動作するためビルド不要 → false で明示的に拒否。
- minimumReleaseAge: 4320 (3日) で公開直後の新バージョンの自動
  取り込みを抑止し、乗っ取り直後の悪性版を回避。緊急時は
  minimumReleaseAgeExclude で個別に即時採用可能。
- pnpm 標準の content-addressable store + 整合性検証。

minimumReleaseAgeExclude について:
pnpm の minimumReleaseAge は解決時に古い版へ自動降格せず検証で弾く
ため、browserslist 系のデータパッケージ
(baseline-browser-mapping / caniuse-lite / electron-to-chromium)
のように毎日リリースされる依存があると、3日クールダウンでは解決の
たびに窓内の最新版を掴み CI の --frozen-lockfile が失敗する。これら
は dev 専用・データのみで dist には一切バンドルされない (公開される
action に含まれない) ため、供給網リスクが小さく除外する。

主な変更:
- package.json: packageManager を pnpm@11.5.0 (SHA512 ピン) へ。
  機能していなかった husky (v4 形式設定・.husky 無し) を撤去し
  依存を削減。
- pnpm-workspace.yaml 新規: サプライチェーン設定を集約。
- yarn.lock 削除 → pnpm-lock.yaml 新規。
- CI (test.yml / windows.yml): pnpm/action-setup + setup-node
  (cache: pnpm) を SHA ピンで追加し、yarn → pnpm へ。
- dist/index.js: 依存をレンジ内最新へ再解決したため ncc バンドルを
  再生成。lib/ は src 由来のため差分なし。
- README / CLAUDE.md / テストコメントの yarn 表記を pnpm へ更新。

検証: pnpm install --frozen-lockfile / build / package / test
(97 passed) をローカルで確認済み。

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@nanasess
nanasess force-pushed the feature/use-pnpm branch from ecc70bd to 8ec4112 Compare June 1, 2026 05:46
@nanasess nanasess changed the title build: yarn から pnpm へ移行しサプライチェーン対策を強化 build: migrate from yarn to pnpm to harden the supply chain Jun 1, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
README.md (1)

164-164: ⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Windows バージョン表記の区切りを修正してください。

Line 164 に不要な空白があり、表の可読性を下げています。

📝 提案差分
-| **Windows** | `windows-latest`, `windows-2025 , windows-2022`   |
+| **Windows** | `windows-latest`, `windows-2025`, `windows-2022`   |
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@README.md` at line 164, The Windows version row in the table contains an
extra space in the cell string "| **Windows** | `windows-latest`, `windows-2025
, windows-2022`   |"; update that cell to consistently format the items and
remove the stray space and trailing spaces so it reads "`windows-latest`,
`windows-2025`, `windows-2022`" (i.e., remove the space before the comma and any
trailing whitespace).
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/test.yml:
- Around line 49-53: Update the two jobs that call actions/setup-node (the test
job and test_default_version job) to disable the pnpm cache when the PR comes
from a fork: replace the unconditional cache: pnpm setting with a conditional
that only sets cache: pnpm when github.event.pull_request.head.repo.fork is
false (i.e., not a fork); specifically modify the actions/setup-node steps so
their cache: pnpm is omitted or set to false for forked PRs and preserved
otherwise.

In @.github/workflows/windows.yml:
- Around line 37-41: The actions/setup-node step currently uses cache: pnpm
unconditionally (refer to the actions/setup-node usage and the pnpm install
--frozen-lockfile step); update the workflow to detect forked PRs (e.g., via
github.event.pull_request.head.repo.fork or comparing github.repository_owner to
github.event.pull_request.head.repo.owner) and either disable cache: pnpm for
forked PRs or derive a trust-isolated cache key (include the repo owner/name or
a trust flag in the cache key) so forks do not share cached pnpm state, and
ensure the pnpm install step still runs without cache when caching is disabled.

---

Outside diff comments:
In `@README.md`:
- Line 164: The Windows version row in the table contains an extra space in the
cell string "| **Windows** | `windows-latest`, `windows-2025 , windows-2022`  
|"; update that cell to consistently format the items and remove the stray space
and trailing spaces so it reads "`windows-latest`, `windows-2025`,
`windows-2022`" (i.e., remove the space before the comma and any trailing
whitespace).
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 4808ddac-c14e-4fd0-b5d9-422daa18221a

📥 Commits

Reviewing files that changed from the base of the PR and between ecc70bd and 8ec4112.

⛔ Files ignored due to path filters (4)
  • dist/index.js is excluded by !**/dist/**
  • dist/index.js.map is excluded by !**/dist/**, !**/*.map
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (8)
  • .github/workflows/test.yml
  • .github/workflows/windows.yml
  • .gitignore
  • CLAUDE.md
  • README.md
  • __tests__/chromedriver-api.test.ts
  • package.json
  • pnpm-workspace.yaml
✅ Files skipped from review due to trivial changes (2)
  • .gitignore
  • tests/chromedriver-api.test.ts
🚧 Files skipped from review as they are similar to previous changes (2)
  • package.json
  • CLAUDE.md

Comment thread .github/workflows/test.yml
Comment thread .github/workflows/windows.yml
actions/setup-node の cache: pnpm が pull_request (fork 含む) で無条件
に有効だと、信頼境界を跨いだキャッシュ汚染の余地が残る。fork PR の
場合のみ cache を空にして無効化し、自リポジトリの push / 同一リポPR
ではキャッシュを維持する。

GitHub Actions 式では空文字が falsy のため、'pnpm' を truthy 側に置く
条件 (fork != true && 'pnpm' || '') で fork 時のみ '' になるようにする。

CodeRabbit のレビュー指摘 (test.yml / windows.yml) に対応。

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@nanasess
nanasess merged commit b875cab into master Jun 1, 2026
99 of 100 checks passed
@nanasess
nanasess deleted the feature/use-pnpm branch June 1, 2026 06:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant