Reproduction steps
Build the Rust CLI from current main. In a workspace with many projects and linked workspace dependencies, run a shared-lockfile deploy:
pnpm --filter app deploy ./output
Profile the lockfile conversion in create_deploy_files. Each local dependency key calls create_file_url_key, which scans the complete all_projects vector and normalizes both paths for every comparison.
Describe the bug
Rust pnpm deploy stores workspace project metadata in a vector. It scans that vector each time it converts a local dependency path to a deployed lockfile key. The conversion runs for local dependency references, package keys, snapshots, and workspace importers.
This makes project lookup scale with the number of local references multiplied by the number of workspace projects. The repeated path normalization also allocates new comparison components during each scan. Large workspaces with many linked packages do unnecessary CPU and allocation work during deploy.
This reproduces on upstream/main at commit 95bb27e1380bd91691e5402aa74e8f80f15e9cfd.
Expected behavior
Rust pnpm deploy should index workspace project metadata once by its normalized comparison path and use constant-time lookups while converting the lockfile. The index should preserve the existing cross-platform path comparison behavior and must not change the generated manifest or lockfile.
Environment
- Rust pnpm CLI built from
main
- Node.js: v26.8.1
- Operating system: macOS 27.0
Written by an agent (Codex, gpt-5.6-sol).
Reproduction steps
Build the Rust CLI from current
main. In a workspace with many projects and linked workspace dependencies, run a shared-lockfile deploy:pnpm --filter app deploy ./outputProfile the lockfile conversion in
create_deploy_files. Each local dependency key callscreate_file_url_key, which scans the completeall_projectsvector and normalizes both paths for every comparison.Describe the bug
Rust
pnpm deploystores workspace project metadata in a vector. It scans that vector each time it converts a local dependency path to a deployed lockfile key. The conversion runs for local dependency references, package keys, snapshots, and workspace importers.This makes project lookup scale with the number of local references multiplied by the number of workspace projects. The repeated path normalization also allocates new comparison components during each scan. Large workspaces with many linked packages do unnecessary CPU and allocation work during deploy.
This reproduces on
upstream/mainat commit95bb27e1380bd91691e5402aa74e8f80f15e9cfd.Expected behavior
Rust
pnpm deployshould index workspace project metadata once by its normalized comparison path and use constant-time lookups while converting the lockfile. The index should preserve the existing cross-platform path comparison behavior and must not change the generated manifest or lockfile.Environment
mainWritten by an agent (Codex, gpt-5.6-sol).