mirror of
https://github.com/Fission-AI/OpenSpec.git
synced 2026-10-02 05:24:34 +08:00
chore(deps): declare pnpm overrides only in pnpm-workspace.yaml (#1816)
The security overrides were declared twice: in pnpm-workspace.yaml, with the advisory comments explaining each pin, and again under package.json's pnpm.overrides. The copies are not additive — pnpm 10 uses package.json's block instead of the workspace list when both are present — and Dependabot rewrites plain-name entries in package.json whenever it bumps the same package. So a routine bump silently displaces the pins that patch advisories, and fails the equality test that guards them (#1812). Keeps one declaration, in the file that carries the reasoning, and asserts the mirror stays gone. Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
aedf4d0c64
commit
e4e112d94f
@@ -1,10 +1,14 @@
|
||||
version: 2
|
||||
|
||||
# Dependabot does not manage two dependency surfaces in this repo:
|
||||
# 1. pnpm `overrides` (pnpm-workspace.yaml + package.json, root and website) —
|
||||
# transitive version pins that remediate advisories Dependabot can't otherwise
|
||||
# reach. It never bumps or removes these; each carries an inline advisory
|
||||
# comment noting the removal condition (see pnpm-workspace.yaml).
|
||||
# 1. pnpm `overrides` (pnpm-workspace.yaml, root and website) — transitive
|
||||
# version pins that remediate advisories Dependabot can't otherwise reach.
|
||||
# It never bumps or removes these; each carries an inline advisory comment
|
||||
# noting the removal condition (see pnpm-workspace.yaml). They live in
|
||||
# pnpm-workspace.yaml only, because Dependabot *does* rewrite a plain-name
|
||||
# override (`postcss: ^8.5.26`) mirrored under package.json's `pnpm.overrides`
|
||||
# — and that block replaces the workspace list rather than merging with it,
|
||||
# so the mirror displaces the real pins. See #1812.
|
||||
# 2. The Nix flake (flake.nix / flake.lock). Update nixpkgs manually with
|
||||
# `nix flake update`; there is no Dependabot ecosystem for Nix. Note that the
|
||||
# pnpmDeps FOD hash in flake.nix must be regenerated on any root lockfile change.
|
||||
|
||||
+1
-8
@@ -85,13 +85,6 @@
|
||||
"pnpm": {
|
||||
"onlyBuiltDependencies": [
|
||||
"esbuild"
|
||||
],
|
||||
"overrides": {
|
||||
"brace-expansion@<=5.0.8": ">=5.0.9 <6",
|
||||
"postcss@<8.5.23": ">=8.5.23 <9",
|
||||
"js-yaml@>=3.0.0 <3.15.1": ">=3.15.1 <4",
|
||||
"js-yaml@>=4.0.0 <4.3.1": ">=4.3.1 <5",
|
||||
"nanoid@<3.3.17": ">=3.3.17 <4"
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
|
||||
@@ -4,6 +4,11 @@ packages:
|
||||
allowBuilds:
|
||||
esbuild@0.28.1: true
|
||||
|
||||
# The only declaration of these. A `pnpm.overrides` block in package.json does not
|
||||
# merge with this list — pnpm 10 uses it *instead of* this file (verified: a lone
|
||||
# entry there produced a lockfile with only that override). Dependabot rewrites
|
||||
# plain-name entries in package.json when it bumps the same package, so a mirrored
|
||||
# copy there both drifts and silently takes precedence over these advisory pins.
|
||||
overrides:
|
||||
brace-expansion@<=5.0.8: '>=5.0.9 <6'
|
||||
postcss@<8.5.23: '>=8.5.23 <9'
|
||||
|
||||
@@ -14,7 +14,7 @@ function readYaml(relativePath: string): Record<string, any> {
|
||||
}
|
||||
|
||||
describe('pnpm workspace configuration', () => {
|
||||
it('keeps root build approval and security overrides compatible across pnpm versions', () => {
|
||||
it('keeps root build approval aligned and security overrides single-sourced', () => {
|
||||
const packageJson = readJson('package.json');
|
||||
const lockfile = readYaml('pnpm-lock.yaml');
|
||||
const workspace = readYaml('pnpm-workspace.yaml');
|
||||
@@ -28,7 +28,11 @@ describe('pnpm workspace configuration', () => {
|
||||
expect(workspace.allowBuilds).toEqual({
|
||||
[`esbuild@${esbuildVersions[0]}`]: true,
|
||||
});
|
||||
expect(workspace.overrides).toEqual(packageJson.pnpm.overrides);
|
||||
// Overrides are declared once, in pnpm-workspace.yaml. A `pnpm.overrides` block
|
||||
// in package.json replaces that list rather than merging with it, and Dependabot
|
||||
// rewrites plain-name entries there when it bumps the same package — so a mirrored
|
||||
// copy silently displaces the pins that patch advisories.
|
||||
expect(packageJson.pnpm.overrides).toBeUndefined();
|
||||
expect(workspace.overrides).toEqual(lockfile.overrides);
|
||||
});
|
||||
|
||||
@@ -46,7 +50,8 @@ describe('pnpm workspace configuration', () => {
|
||||
expect(workspace.allowBuilds).toEqual({
|
||||
[`esbuild@${esbuildVersions[0]}`]: true,
|
||||
});
|
||||
expect(workspace.overrides).toEqual(packageJson.pnpm.overrides);
|
||||
// Single-sourced in website/pnpm-workspace.yaml, for the reason above.
|
||||
expect(packageJson.pnpm.overrides).toBeUndefined();
|
||||
expect(workspace.overrides).toEqual(lockfile.overrides);
|
||||
});
|
||||
|
||||
|
||||
@@ -36,13 +36,6 @@
|
||||
"pnpm": {
|
||||
"onlyBuiltDependencies": [
|
||||
"esbuild"
|
||||
],
|
||||
"overrides": {
|
||||
"postcss": "^8.5.28",
|
||||
"sharp": "^0.35.3",
|
||||
"brace-expansion@<=5.0.8": ">=5.0.9 <6",
|
||||
"fast-uri@<3.1.6": "^3.1.6",
|
||||
"nanoid@<3.3.17": ">=3.3.17 <4"
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
|
||||
@@ -4,6 +4,11 @@ packages:
|
||||
allowBuilds:
|
||||
esbuild@0.28.2: true
|
||||
|
||||
# The only declaration of these. A `pnpm.overrides` block in package.json does not
|
||||
# merge with this list — pnpm 10 uses it *instead of* this file (verified: a lone
|
||||
# entry there produced a lockfile with only that override). Dependabot rewrites
|
||||
# plain-name entries in package.json when it bumps the same package, so a mirrored
|
||||
# copy there both drifts and silently takes precedence over these advisory pins.
|
||||
overrides:
|
||||
postcss: ^8.5.28
|
||||
sharp: ^0.35.3
|
||||
|
||||
Reference in New Issue
Block a user