Skip to content

Peer dependencies from non-default package sources are incorrectly installed #10417

Description

@bcheidemann

Verify latest release

  • I verified that the issue exists in the latest pnpm release

pnpm version

10.27.0

Which area(s) of pnpm are affected? (leave empty if unsure)

CLI

Link to the code that reproduces this issue or a replay of the bug

https://github.com/bcheidemann/pnpm-reproduction-peer-dep-sources

Reproduction steps

$ cd ~/repos
$ mkdir pnpm-reproduction-peer-dep-sources
$ cd pnpm-reproduction-peer-dep-sources
$ pnpm init
Wrote to /home/[USER]/repos/pnpm-reproduction-peer-dep-sources/package.json

{
  "name": "pnpm-reproduction-peer-dep-sources",
  "version": "1.0.0",
  "description": "",
  "main": "index.js",
  "scripts": {
    "test": "echo \"Error: no test specified\" && exit 1"
  },
  "keywords": [],
  "author": "",
  "license": "ISC",
  "packageManager": "pnpm@10.27.0"
}
$ pnpm add jsr:@std/html --save-peer
Packages: +1
+
Progress: resolved 1, reused 1, downloaded 0, added 1, done

dependencies:
+ @std/html <- @jsr/std__html 1.0.5

peerDependencies:
+ @std/html jsr:^1.0.5

devDependencies:
+ @std/html jsr:^1.0.5 already in devDependencies, was not moved to dependencies.

Done in 424ms using pnpm v10.27.0
$ cat package.json
{
  "name": "pnpm-reproduction-peer-dep-sources",
  "version": "1.0.0",
  "description": "",
  "main": "index.js",
  "scripts": {
    "test": "echo \"Error: no test specified\" && exit 1"
  },
  "keywords": [],
  "author": "",
  "license": "ISC",
  "packageManager": "pnpm@10.27.0",
  "devDependencies": {
    "@std/html": "jsr:^1.0.5"
  },
  "peerDependencies": {
    "@std/html": "jsr:^1.0.5"
  }
}
$ pnpm add sass
 ERR_PNPM_INVALID_PEER_DEPENDENCY_SPECIFICATION  The peerDependencies field named '@std/html' of package 'pnpm-reproduction-peer-dep-sources' has an invalid value: 'jsr:^1.0.5'

The values in peerDependencies should be either a valid semver range, a `workspace:` spec, or a `catalog:` spec

Describe the Bug

When running pnpm add <source>:<package> --save-peer the package is added to the package.json like this:

  "devDependencies": {
+   "<package>": "<source>:<version>"
  },
  "peerDependencies": {
+   "<package>": "<source>:<version>"
  }

As per this comment, the current behavior is incorrect, since source specifiers are not allowed in the version constraints of peerDependencies:

I don't know why it worked in the past. peer dependencies were always meant to only be semver specs. Someone noticed the issue and it was fixed

Indeed, running pnpm add <package> will then result in an error:

 ERR_PNPM_INVALID_PEER_DEPENDENCY_SPECIFICATION  The peerDependencies field named '@std/html' of package 'pnpm-reproduction-peer-dep-sources' has an invalid value: 'jsr:^1.0.5'

The values in peerDependencies should be either a valid semver range, a `workspace:` spec, or a `catalog:` spec

Expected Behavior

When running pnpm add <source>:<package> --save-peer, only the version constraint should be added to the peerDependencies array of the package.json, while the full <source>:<version> should be added to the devDependencies as normal:

  "devDependencies": {
    "<package>": "<source>:<version>"
  },
  "peerDependencies": {
-   "<package>": "<source>:<version>"
+   "<package>": "<version>"
  }

Which Node.js version are you using?

v24.11.1

Which operating systems have you used?

  • macOS
  • Windows
  • Linux

If your OS is a Linux based, which one it is? (Include the version if relevant)

Ubuntu 24 LTS

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions