chore(deps): declare pnpm overrides only in pnpm-workspace.yaml (#1816)

The security overrides were declared twice: in pnpm-workspace.yaml, with
the advisory comments explaining each pin, and again under
package.json's pnpm.overrides. The copies are not additive — pnpm 10
uses package.json's block instead of the workspace list when both are
present — and Dependabot rewrites plain-name entries in package.json
whenever it bumps the same package. So a routine bump silently
displaces the pins that patch advisories, and fails the equality test
that guards them (#1812).

Keeps one declaration, in the file that carries the reasoning, and
asserts the mirror stays gone.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Clay Good
2026-09-09 17:47:22 +00:00
committed by GitHub
co-authored by Claude Opus 5
parent aedf4d0c64
commit e4e112d94f
6 changed files with 28 additions and 23 deletions
+8 -4
View File
@@ -1,10 +1,14 @@
version: 2
# Dependabot does not manage two dependency surfaces in this repo:
# 1. pnpm `overrides` (pnpm-workspace.yaml + package.json, root and website) —
# transitive version pins that remediate advisories Dependabot can't otherwise
# reach. It never bumps or removes these; each carries an inline advisory
# comment noting the removal condition (see pnpm-workspace.yaml).
# 1. pnpm `overrides` (pnpm-workspace.yaml, root and website) — transitive
# version pins that remediate advisories Dependabot can't otherwise reach.
# It never bumps or removes these; each carries an inline advisory comment
# noting the removal condition (see pnpm-workspace.yaml). They live in
# pnpm-workspace.yaml only, because Dependabot *does* rewrite a plain-name
# override (`postcss: ^8.5.26`) mirrored under package.json's `pnpm.overrides`
# — and that block replaces the workspace list rather than merging with it,
# so the mirror displaces the real pins. See #1812.
# 2. The Nix flake (flake.nix / flake.lock). Update nixpkgs manually with
# `nix flake update`; there is no Dependabot ecosystem for Nix. Note that the
# pnpmDeps FOD hash in flake.nix must be regenerated on any root lockfile change.
+1 -8
View File
@@ -85,13 +85,6 @@
"pnpm": {
"onlyBuiltDependencies": [
"esbuild"
],
"overrides": {
"brace-expansion@<=5.0.8": ">=5.0.9 <6",
"postcss@<8.5.23": ">=8.5.23 <9",
"js-yaml@>=3.0.0 <3.15.1": ">=3.15.1 <4",
"js-yaml@>=4.0.0 <4.3.1": ">=4.3.1 <5",
"nanoid@<3.3.17": ">=3.3.17 <4"
}
]
}
}
+5
View File
@@ -4,6 +4,11 @@ packages:
allowBuilds:
esbuild@0.28.1: true
# The only declaration of these. A `pnpm.overrides` block in package.json does not
# merge with this list — pnpm 10 uses it *instead of* this file (verified: a lone
# entry there produced a lockfile with only that override). Dependabot rewrites
# plain-name entries in package.json when it bumps the same package, so a mirrored
# copy there both drifts and silently takes precedence over these advisory pins.
overrides:
brace-expansion@<=5.0.8: '>=5.0.9 <6'
postcss@<8.5.23: '>=8.5.23 <9'
+8 -3
View File
@@ -14,7 +14,7 @@ function readYaml(relativePath: string): Record<string, any> {
}
describe('pnpm workspace configuration', () => {
it('keeps root build approval and security overrides compatible across pnpm versions', () => {
it('keeps root build approval aligned and security overrides single-sourced', () => {
const packageJson = readJson('package.json');
const lockfile = readYaml('pnpm-lock.yaml');
const workspace = readYaml('pnpm-workspace.yaml');
@@ -28,7 +28,11 @@ describe('pnpm workspace configuration', () => {
expect(workspace.allowBuilds).toEqual({
[`esbuild@${esbuildVersions[0]}`]: true,
});
expect(workspace.overrides).toEqual(packageJson.pnpm.overrides);
// Overrides are declared once, in pnpm-workspace.yaml. A `pnpm.overrides` block
// in package.json replaces that list rather than merging with it, and Dependabot
// rewrites plain-name entries there when it bumps the same package — so a mirrored
// copy silently displaces the pins that patch advisories.
expect(packageJson.pnpm.overrides).toBeUndefined();
expect(workspace.overrides).toEqual(lockfile.overrides);
});
@@ -46,7 +50,8 @@ describe('pnpm workspace configuration', () => {
expect(workspace.allowBuilds).toEqual({
[`esbuild@${esbuildVersions[0]}`]: true,
});
expect(workspace.overrides).toEqual(packageJson.pnpm.overrides);
// Single-sourced in website/pnpm-workspace.yaml, for the reason above.
expect(packageJson.pnpm.overrides).toBeUndefined();
expect(workspace.overrides).toEqual(lockfile.overrides);
});
+1 -8
View File
@@ -36,13 +36,6 @@
"pnpm": {
"onlyBuiltDependencies": [
"esbuild"
],
"overrides": {
"postcss": "^8.5.28",
"sharp": "^0.35.3",
"brace-expansion@<=5.0.8": ">=5.0.9 <6",
"fast-uri@<3.1.6": "^3.1.6",
"nanoid@<3.3.17": ">=3.3.17 <4"
}
]
}
}
+5
View File
@@ -4,6 +4,11 @@ packages:
allowBuilds:
esbuild@0.28.2: true
# The only declaration of these. A `pnpm.overrides` block in package.json does not
# merge with this list — pnpm 10 uses it *instead of* this file (verified: a lone
# entry there produced a lockfile with only that override). Dependabot rewrites
# plain-name entries in package.json when it bumps the same package, so a mirrored
# copy there both drifts and silently takes precedence over these advisory pins.
overrides:
postcss: ^8.5.28
sharp: ^0.35.3