Skip to content

build: update Node.js to v26 and pnpm to v12 - #48

Merged
dangreen merged 2 commits into
mainfrom
build/node-26
Oct 6, 2026
Merged

dangreen merged 2 commits into
mainfrom
build/node-26

Conversation

@dangreen

@dangreen dangreen commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

Why

The repository was developed on Node.js 24.20.0 and pnpm 11.9.0, and CI ran on Node.js 24 alone, so nothing checked the floor of engines.node, >=22. Node.js 26 is the latest release line and becomes an LTS on 2026-10-28, while the packages keep supporting Node.js 22 until its end of life on 2027-04-30.

pnpm 12 is the latest release, and its breaking changes leave the workspace alone: pnpm 12 recognizes every setting of pnpm-workspace.yaml, nothing passes --frozen-lockfile false, no dependency comes from git, and engineStrict is off. The one change it asks for is in the lockfile: pnpm 12, like pnpm 11.28, compares the publishConfig.linkDirectory of a package with the lockfile, so a frozen install of the old lockfile fails with ERR_PNPM_OUTDATED_LOCKFILE. That is also why #47 pinned CI to pnpm 11.9.0.

What

  • .tool-versions pins Node.js 26.10.0, the latest 26, and pnpm 12.9.1, the version of the latest tag. Every actions/setup-node step reads Node.js through node-version-file, so a bump of the file moves local development and CI together, and every pnpm/action-setup step asks for pnpm 12 instead of the 11.9.0 pinned in build: limit concurrency of workspace scripts to CPU cores #47.
  • The unit job runs on a matrix of Node.js 22, the floor the packages declare, and the version of .tool-versions, and uploads coverage from the latter alone.
  • @types/node goes from ^24 back to ^22, the floor, in the root and the 7 packages that use it, so the types catch an API of a newer Node.js. chore(deps): update dependency @types/node to v24 #32 had moved it to ^24.
  • The lockfile moves the 8 importers from @types/node 24.13.3 to 22.20.1, which it already held, and re-keys the peer variants that take @types/node. The re-resolution also records the optional platform packages of satteri 0.10.5, which the old lockfile missed. On top, it records linkDirectory: false for the 11 packages whose publishConfig sets it, the way pnpm 12 writes it. No other version changes.

Notes

  • Not breaking: engines.node stays >=22 in the packages and the root, so nothing gets released.
  • Renovate keeps no rule for @types/node, so it is going to offer ^24 again, as in chore(deps): update dependency @types/node to v24 #32.
  • The unit check now reports as unit (22) and unit (.tool-versions). No branch protection or ruleset requires the old name.
  • minimumReleaseAge has applied since pnpm 11, so the move to 12 changes nothing about it, and minimumReleaseAgeExclude stays as it is.
  • Checked on Node.js 26.10.0: the workflows parse, a frozen install from scratch on pnpm 11.9.0 and on pnpm 12.9.1 gives no engine warnings, a plain install on pnpm 12 leaves the lockfile alone, the types of the 7 packages with @types/node pass on ^22, the unit tests of core and cli pass on Node.js 26 and 22, lint of core and cli passes, size-limit of imgproxy measures the same 806 B as on Node.js 24, on pnpm 12 the build of runtime through pnpm run triggers no install before the script, and lint-package-json passes through pnpm dlx on both versions of pnpm.
  • The Renovate PRs chore(deps): update dependency @types/node to v24 #45, chore(deps): update dependency pnpm to v12 - autoclosed #44 and chore(deps): update dependency pnpm to v11.28.5 - autoclosed #21, which bump Node.js and pnpm, become obsolete.

Pin Node.js 26.10.0 in `.tool-versions` and make every CI job read it. The unit job also
runs on Node.js 22, the floor of `engines`, which stays as it is, and `@types/node` goes
back to `^22` to match that floor.
@coveralls

coveralls commented Oct 6, 2026 •

Copy link
Copy Markdown

Coverage Report for CI Build 37503015236

Coverage remained the same at 93.859%

Details

  • Coverage remained the same as the base build.
  • Patch coverage: No coverable lines changed in this PR.
  • No coverage regressions found.

Uncovered Changes

No uncovered changes found.

Coverage Regressions

No coverage regressions found.


Coverage Stats

Coverage Status
Relevant Lines: 889
Covered Lines: 842
Line Coverage: 94.71%
Relevant Branches: 658
Covered Branches: 610
Branch Coverage: 92.71%
Branches in Coverage %: Yes
Coverage Strength: 158891.75 hits per line

💛 - Coveralls

Pin pnpm 12.9.1 and ask CI for pnpm 12. Settings need no migration from pnpm 11. The lockfile
records `linkDirectory: false` of the 11 packages that set it, which a frozen install of pnpm 12
checks, and pnpm 12 finds it up to date with that alone.
@dangreen dangreen mentioned this pull request Oct 6, 2026
@dangreen dangreen changed the title build: update Node.js to v26 build: update Node.js to v26 and pnpm to v12 Oct 6, 2026
@dangreen
dangreen merged commit 952e772 into main Oct 6, 2026
15 of 17 checks passed
@dangreen
dangreen deleted the build/node-26 branch October 6, 2026 17:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants