Skip to content

chore: upgrade pnpm from 9 to 11 - #117

Open
totigm wants to merge 1 commit into
mainfrom
chore/pnpm-11
Open

totigm wants to merge 1 commit into
mainfrom
chore/pnpm-11

Conversation

@totigm

@totigm totigm commented Sep 1, 2026

Copy link
Copy Markdown
Owner

Unblocks #109. @changesets/cli@3 declares "engines": { "pnpm": ">=10.0.0" } and this repo pins pnpm@9.15.0 via packageManager, so that bump cannot land until pnpm moves. Went to 11 rather than the minimum 10 because the whole suite was verifiable locally and there is no reason to do this twice.

The migration is two files, but it is not a no-op

package.json and pnpm-workspace.yaml. The lockfile stays at lockfileVersion: 9.0 and needs no regeneration — --frozen-lockfile passes untouched.

The part that matters is that pnpm 10 stopped running dependency install scripts unless they are allowed explicitly, and pnpm 11 renamed that setting from the onlyBuiltDependencies list to the allowBuilds map. A clean install reports:

[ERR_PNPM_IGNORED_BUILDS] Ignored build scripts:
  esbuild@0.27.7, esbuild@0.28.1, ffmpeg-static@5.3.0, lefthook@2.1.10

All three packages genuinely need their script, and all three fail quietly:

Package What its script does What breaks without it
esbuild fetches the platform binary tsup and vite — the whole build
ffmpeg-static fetches the ffmpeg binary @humanjs/recorder video and GIF export. The library still imports and every export fails at runtime
lefthook installs the git hook binary the repo's pre-commit

ffmpeg-static is the dangerous one. Nothing in lint/typecheck/test/build touches it, so a migration that skipped this would go green in CI and ship a recorder that cannot export.

Verification

Full suite on pnpm 11 after a clean install (node_modules deleted, --frozen-lockfile): lint, typecheck (10/10), test (9/9), build (7/7), check:exports (13/13).

Then, because the check suite provably cannot catch the ffmpeg-static failure, pnpm demo:record end to end — which produced a 562 KB mp4, a 3.2 MB GIF, a timeline, and both code exports. That is the real proof.

Notes

  • No workflow changes needed: all four use pnpm/action-setup@v6, which reads the version from packageManager.
  • The allowBuilds block carries a comment explaining why each entry is there, and warns that pnpm approve-builds rewrites the file and drops those comments.
  • After this lands, chore(deps-dev): bump @changesets/cli from 2.31.0 to 3.0.1 #109 needs a rebase and should go green.

Unblocks @changesets/cli 3 (#109), which declares engines pnpm >=10.0.0
and cannot be installed while this repo pins pnpm@9.15.0.

The migration is two files -- the lockfile stays at v9.0 and needs no
regeneration -- but it is not a no-op, because pnpm 10 stopped running
dependency install scripts unless allowed explicitly and pnpm 11 renamed
that setting from the onlyBuiltDependencies list to the allowBuilds map.

Three packages here need theirs, and all three fail quietly:

  esbuild        platform binary; tsup and vite are dead without it.
  ffmpeg-static  the ffmpeg binary @humanjs/recorder shells out to for
                 video and GIF export -- the library still imports, and
                 every export breaks at runtime.
  lefthook       the git hook binary pre-commit relies on.

Verified beyond the check suite by running demo:record end to end, which
produced mp4, GIF, timeline and both code exports.
@vercel

vercel Bot commented Sep 1, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
humanjs Ready Ready Preview Sep 1, 2026 1:16pm UTC

This branch was successfully deployed

1 active deployment
Preview — c017db48 Deployed Sep 1, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant