Repository navigation
chore(ci): commit pnpm-lock.yaml and install frozen - #12
Merged
Merged
Conversation
Nothing pinned what this package shipped. .gitignore excluded every lockfile and all three CI jobs ran npm install, so each test run, build and publish resolved fresh from the registry — the published artifact was never built from a reviewed tree, and a bad transitive release would land with no diff to show for it. This package runs in every wms service, so that reproducibility gap matters. Standardises on pnpm to match the rest of the org, pinned by packageManager, and moves CI to pnpm install --frozen-lockfile. Node version comes from one env value per workflow instead of being repeated three times. CONTRIBUTING said to tag releases with npm version, contradicting the release skill and the actual publish trigger; rewritten to match how releases really work. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #10 (
fix/filestore-contract), since that is still unmerged. Retarget tomainonce #10 lands.The gap
.gitignoreexcludedpackage-lock.json,pnpm-lock.yamlandyarn.lock, and all three CI jobs rannpm install— nevernpm ci. So nothing pinned what this package shipped:This package is loaded by every wms service in production, which is what makes it worth fixing first.
Change
pnpm-lock.yamlis now committed (4,972 lines, 344 resolutions) and CI installs--frozen-lockfile, so a dependency change has to show up as a reviewable diff.Standardised on pnpm rather than npm: it matches wms and the rest of the org, the repo already carried
pnpm-workspace.yaml, and.claude/skills/release/SKILL.mdalready documentedpnpmcommands. The version is pinned viapackageManagerinpackage.json, whichpnpm/action-setupreads — so CI and local use the same pnpm.Also folded in, since both were touched anyway:
env: NODE_VERSIONper workflow.actions/setup-nodegetscache: pnpm, which the lockfile makes possible.CONTRIBUTING.mdsaid "Add tag for a minor/major release bynpm version minor" — wrong on two counts. It contradicted.claude/skills/release/SKILL.md("Do NOT create git tags") and misidentified the publish trigger, which isrelease: created, not a push. That contradiction is what sent PR chore(deps): fastify-plugin 6, lazy-load cloud SDKs, 100% coverage #6 wrong originally, so leaving it in place would keep costing. Rewritten to describe setup, the review rules onmain, and how releases actually work..gitignorealso carried service-template cruft (config/*,!config/dev.yml,data,bin,env) for directories a plugin library does not have.Deliberately not included
--provenanceon publish. It is the natural companion to a lockfile, but GitHub Packages does not accept provenance attestations — adding it would break the publish job, which is the one workflow that cannot be safely tested before it runs for real. Left alone, with a comment recording why.Verification
rm -rf node_modules && pnpm install --frozen-lockfilesucceeds from the committed lockfile, build is clean, and the suite is unchanged at 127 tests, 100% coverage on statements, branches, functions and lines.Note the workflows take no input from
github.eventorgithub.head_ref, so there is no injection surface in the changed files.