Skip to content

Move to pnpm 12 - #19

Merged
silveltman merged 1 commit into
mainfrom
chore/pnpm-12
Oct 2, 2026
Merged

silveltman merged 1 commit into
mainfrom
chore/pnpm-12

Conversation

@silveltman

@silveltman silveltman commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Moves the repository to pnpm 12.8.1, like the rest of the organization.

  • packageManager is pnpm@12.8.1. Netlify and the organization Check read it through Corepack.
  • The lockfile keeps every resolved version; pnpm 12 only adds a record of its own version.
  • Where present: docs name pnpm 12.8.1, workflows pin pnpm/action-setup@v6.1.0 (its v6 tag is still 6.0.10, which cannot install pnpm 12), and PNPM_VERSION is gone from netlify.toml.

The trust policy comes separately in the security/pnpm-trust-policy pull request, which only changes pnpm-workspace.yaml.

Files: package.json pnpm-lock.yaml

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated the project’s package management tooling version. No user-facing changes are included in this update.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 2, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 06a839bd-843f-432e-8212-98695b0c1397

📥 Commits

Reviewing files that changed from the base of the PR and between a22b6e1 and c90af58.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (1)
  • package.json

Limit details: You’ve used all 10 included reviews currently available.


📝 Walkthrough

Walkthrough

The packageManager declaration in package.json changes from pnpm@11.28.0 to pnpm@12.8.1.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to c90af

The repository consistently records pnpm 12.8.1, with no conflicting deployment version evident. No actionable merge risk is established.

Security Architecture Review

Security architecture risk: 🔵 Low · up to c90af

The changes consistently select pnpm 12.8.1 without changing application scripts or configured installation safeguards. No newly weakened security control was established. Deployment-host version selection and installation recovery behavior remain unverified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The directly affected security surface is package installation and build execution in environments that honor the declaration. The supplied changes do not establish new application-facing authority; build-host credentials and downstream exposure are not documented.

Trust Boundaries and Controls

  • observed — Netlify configuration requests frozen-lockfile installation and disables dependency scripts and pnpmfile execution through flags and configuration variables. These pre-existing settings are counterevidence to a source-level removal of installation safeguards, not proof of their enforcement by the selected host binary.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description check ✅ Passed The description clearly explains the move to pnpm 12.8.1 and identifies related repository updates.
Title check ✅ Passed The title clearly and concisely describes the main change: moving the repository to pnpm 12.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.

Usage-based review receipt

  • Mode: Continue automatically
  • Reviewed files: 1
  • Waived: $0.25 (charged $0.00)
  • View usage details

Note

This review exceeded your plan’s limits and used usage-based reviews—free during trial, billed after paid activation unless disabled. Manage usage-based reviews.


Comment @coderabbitai help to get the list of available commands.

@silveltman
silveltman merged commit 7cb9fec into main Oct 2, 2026
3 checks passed
@silveltman
silveltman deleted the chore/pnpm-12 branch October 2, 2026 17:55
@netlify

netlify Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for silveltman ready!

Name Link
🔨 Latest commit c90af58
🔍 Latest deploy log https://app.netlify.com/projects/silveltman/deploys/6abfee2c5a900e000855ddd8
😎 Deploy Preview https://deploy-preview-19--silveltman.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant