Skip to content

pnpm audit --fix override should respect the savePrefix setting or --save-exact option #11523

Description

@anttis

Verify latest release

  • I verified that the issue exists in the latest pnpm release

pnpm version

No response

Which area(s) of pnpm are affected? (leave empty if unsure)

No response

Link to the code that reproduces this issue or a replay of the bug

https://github.com/anttis/repros/tree/main/pnpm-audit-fix-save-prefix

Reproduction steps

  1. With a project with a vulnerable dependency, set a savePrefix: '' setting into the pnpm-workspace.yaml config.
  2. Run pnpm install
  3. Run pnpm audit --fix override
  4. Observe that caret version ranges are used in the overrides.

Describe the Bug

pnpm audit --fix override uses caret version ranges regardless of the version range (savePrefix) that the user has configured.

(...And this will most likely lead to situations where e.g. Renovate will do a PR that will strip the caret if it's configured to use pinned versions)

Expected Behavior

The overrides should use the same prefix that the user has configured or support a --save-exact kind of option.

Which Node.js version are you using?

v24.15.0

Which operating systems have you used?

  • macOS
  • Windows
  • Linux

If your OS is a Linux based, which one it is? (Include the version if relevant)

No response

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions