Conversation
Unblocks @changesets/cli 3 (#109), which declares engines pnpm >=10.0.0 and cannot be installed while this repo pins pnpm@9.15.0. The migration is two files -- the lockfile stays at v9.0 and needs no regeneration -- but it is not a no-op, because pnpm 10 stopped running dependency install scripts unless allowed explicitly and pnpm 11 renamed that setting from the onlyBuiltDependencies list to the allowBuilds map. Three packages here need theirs, and all three fail quietly: esbuild platform binary; tsup and vite are dead without it. ffmpeg-static the ffmpeg binary @humanjs/recorder shells out to for video and GIF export -- the library still imports, and every export breaks at runtime. lefthook the git hook binary pre-commit relies on. Verified beyond the check suite by running demo:record end to end, which produced mp4, GIF, timeline and both code exports.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Unblocks #109.
@changesets/cli@3declares"engines": { "pnpm": ">=10.0.0" }and this repo pinspnpm@9.15.0viapackageManager, so that bump cannot land until pnpm moves. Went to 11 rather than the minimum 10 because the whole suite was verifiable locally and there is no reason to do this twice.The migration is two files, but it is not a no-op
package.jsonandpnpm-workspace.yaml. The lockfile stays atlockfileVersion: 9.0and needs no regeneration —--frozen-lockfilepasses untouched.The part that matters is that pnpm 10 stopped running dependency install scripts unless they are allowed explicitly, and pnpm 11 renamed that setting from the
onlyBuiltDependencieslist to theallowBuildsmap. A clean install reports:All three packages genuinely need their script, and all three fail quietly:
esbuildtsupandvite— the whole buildffmpeg-staticffmpegbinary@humanjs/recordervideo and GIF export. The library still imports and every export fails at runtimelefthookffmpeg-staticis the dangerous one. Nothing inlint/typecheck/test/buildtouches it, so a migration that skipped this would go green in CI and ship a recorder that cannot export.Verification
Full suite on pnpm 11 after a clean install (
node_modulesdeleted,--frozen-lockfile):lint,typecheck(10/10),test(9/9),build(7/7),check:exports(13/13).Then, because the check suite provably cannot catch the
ffmpeg-staticfailure,pnpm demo:recordend to end — which produced a 562 KB mp4, a 3.2 MB GIF, a timeline, and both code exports. That is the real proof.Notes
pnpm/action-setup@v6, which reads the version frompackageManager.allowBuildsblock carries a comment explaining why each entry is there, and warns thatpnpm approve-buildsrewrites the file and drops those comments.