-
Notifications
You must be signed in to change notification settings - Fork 0
chore: bump pnpm to 12.2.1 #9
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: qa/agent-sveltejs-kit/pr-09-17006/base
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -41,7 +41,7 @@ | |
| "oxfmt": "^0.62.0", | ||
| "vitest": "catalog:" | ||
| }, | ||
| "packageManager": "pnpm@12.0.0+sha512.9e2e3dc3911995868dc94b8175c217c27e95408fa03b4a22749778f2b34f773b77cdd3b39ede8171b22fcd53be6a35342e9fac9948a68ef58df6488ce89a7e67", | ||
| "packageManager": "pnpm@12.2.1+sha512.f55ca68aacb9eb5ab69c66f828a98af89a32286703aef1f8da131ca7eab4d677f34bfa85e186467a919c0799df8b6f4aa240f7dc2919b33b3273190104162616", | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Shipwright · HIGH The new pnpm 12.2.1 integrity hash is introduced without any evidence of verification against a trusted source or changelog review. Impact: The new pnpm 12.2.1 integrity hash is introduced without any evidence of verification against a trusted source or changelog review. Supply-chain policy should require checking release notes and CVE advisories for the package manager before merging a toolchain bump; the diff alone provides no such evidence. Suggested fix: Review the cited evidence, fix the risk if confirmed, and rerun Shipwright. |
||
| "engines": { | ||
| "pnpm": ">=11.0.0" | ||
| } | ||
|
|
||
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Shipwright · HIGH
The packageManager field is bumped from pnpm 12.0.0 to 12.2.1 while the engines.pnpm constraint remains '>=11.0.0'.
Impact: The packageManager field is bumped from pnpm 12.0.0 to 12.2.1 while the engines.pnpm constraint remains '>=11.0.0'. This allows contributors running pnpm 11.x to install with a lockfile generated by pnpm 12.2.1, which can produce inconsistent dependency resolution, corrupted node_modules, or CI failures that only appear on certain machines. The engine floor should be raised to match the new packageManager version.
Suggested fix: Review the cited evidence, fix the risk if confirmed, and rerun Shipwright.