Repository navigation
chore: migrate from npm to pnpm - #88
Open
ivoIturrieta wants to merge 2 commits into
Open
ivoIturrieta wants to merge 2 commits into
ivoIturrieta wants to merge 2 commits into
Conversation
Replace both npm lockfiles with a single pnpm-lock.yaml, converted with `pnpm import` so every resolved version carries over. demo/ becomes a pnpm workspace package, so one `pnpm install` sets up everything. pnpm doesn't run a dependency's install scripts unless pnpm-workspace.yaml allows it, and fails the install when an unreviewed one appears. esbuild is the only dependency with one; its postinstall is a startup optimization, so it's denied. devEngines.packageManager makes `npm install`, `npm ci` and `npm run` refuse to run. pmOnFail is set to ignore because otherwise pnpm writes its own version into the lockfile as a second YAML document, which GitHub's dependency graph can't read yet. CI installs with pnpm. pnpm 11 needs Node 22.13+, so the test matrix uses the standalone pnpm build to keep testing on Node 20. Dependabot gets a one-day cooldown to match pnpm's minimumReleaseAge. The unused netlify-build script is removed; the demo deploys from Vercel. dist/ is byte-identical to the npm build. The packed package.json gains devEngines and no longer lists the prepare and prepublishOnly scripts. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
npm treats demo/ as a separate project, so the root devEngines didn't apply there: `npm install` in demo/ succeeded, wrote its own package-lock.json and ran dependency install scripts (fsevents). demo/package.json now carries the same devEngines block, so `npm install`, `npm ci` and `npm run` stop with EBADDEVENGINES there as well. pnpm and the lockfile are unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ahmed-alaaeldin-saad
approved these changes
Oct 5, 2026
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Replace both npm lockfiles with a single pnpm-lock.yaml, converted with
pnpm importso every resolved version carries over. demo/ becomes a pnpm workspace package, so onepnpm installsets up everything.pnpm doesn't run a dependency's install scripts unless pnpm-workspace.yaml allows it, and fails the install when an unreviewed one appears. esbuild is the only dependency with one; its postinstall is a startup optimization, so it's denied.
devEngines.packageManager makes
npm install,npm ciandnpm runrefuse to run. pmOnFail is set to ignore because otherwise pnpm writes its own version into the lockfile as a second YAML document, which GitHub's dependency graph can't read yet.CI installs with pnpm. pnpm 11 needs Node 22.13+, so the test matrix uses the standalone pnpm build to keep testing on Node 20. Dependabot gets a one-day cooldown to match pnpm's minimumReleaseAge.
The unused netlify-build script is removed; the demo deploys from Vercel.
dist/ is byte-identical to the npm build. The packed package.json gains devEngines and no longer lists the prepare and prepublishOnly scripts.