Skip to content

chore: pin pnpm to exact version 12.4.2 - #2036

Merged
dinwwwh merged 1 commit into
middleapi:mainfrom
dinwwwh:claude/cloudflare-worker-build-82d8b6
Sep 17, 2026
Merged

dinwwwh merged 1 commit into
middleapi:mainfrom
dinwwwh:claude/cloudflare-worker-build-82d8b6

Conversation

@dinwwwh

@dinwwwh dinwwwh commented Sep 17, 2026

Copy link
Copy Markdown
Member

Pins pnpm to exactly 12.4.2 in devEngines.packageManager instead of the ^12.4.1 range, and records 12.4.2 in pnpm-lock.yaml. This unblocks the docs deploy and stops future pnpm releases from breaking it. Cloudflare Workers Builds runs pnpm through Corepack, which since 0.36.0 (nodejs/corepack#892) resolves a devEngines range to the newest pnpm on npm, and pnpm does not switch to the lockfile's version when Corepack starts it. Every new 12.x release (12.4.2 came out on September 15) therefore failed pnpm install --frozen-lockfile with ERR_PNPM_FROZEN_LOCKFILE_WITH_OUTDATED_LOCKFILE until the lockfile was refreshed.

Behavior

  • Corepack always runs the pinned pnpm, so new pnpm releases no longer break the Workers build.
  • Running any other pnpm 12.x locally still switches to the pinned version, as before.
  • Upgrading pnpm is an explicit change: set the new version in devEngines.packageManager.version, then run pnpm install --lockfile-only.
  • The lockfile diff only touches the packageManagerDependencies block and the pnpm / @pnpm/exe.* entries.

Testing

  • With Corepack 0.36.0, CI=true and cold caches, pnpm install --frozen-lockfile reproduces the deploy error on main and passes on this branch with pnpm 12.4.2.
  • With the exact pin set one release behind npm (12.4.1 while 12.4.2 is out), Corepack still runs 12.4.1, and pnpm 12.4.2 started without Corepack switches to 12.4.1.
  • eslint and sherif pass.

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No new issues found.

Reviewed changes

  • Pin pnpm to exact 12.4.2 in package.json:9 — replaces the ^12.4.1 range so Corepack resolves a deterministic version instead of always fetching the newest 12.x.
  • Refresh pnpm-lock.yaml — packageManagerDependencies.pnpm and every pnpm / @pnpm/exe.* package + snapshot entry move to 12.4.2, with no 12.4.1 references left behind.

Verified the pnpm@12.4.2 and @pnpm/exe.linux-x64@12.4.2 integrity hashes against the npm registry (exact match), and confirmed the cited Corepack mechanism — nodejs/corepack#892, shipped in 0.36.0 — does resolve a devEngines range to the newest matching release, so the exact pin is what makes Corepack deterministic. pnpm/action-setup@v6 (CI passes no version input) handles an exact devEngines version fine, and there is no competing packageManager field. No minimumReleaseAge gate is actually configured, so the release's age is not a concern.

Pullfrog  | View workflow run | Using DeepSeek Flash (free via Pullfrog for OSS) | 𝕏

@pkg-pr-new

pkg-pr-new Bot commented Sep 17, 2026

Copy link
Copy Markdown
More templates

@orpc/ai-sdk

npm i https://pkg.pr.new/@orpc/ai-sdk@2036

@orpc/arktype

npm i https://pkg.pr.new/@orpc/arktype@2036

@orpc/bun

npm i https://pkg.pr.new/@orpc/bun@2036

@orpc/client

npm i https://pkg.pr.new/@orpc/client@2036

@orpc/cloudflare

npm i https://pkg.pr.new/@orpc/cloudflare@2036

@orpc/contract

npm i https://pkg.pr.new/@orpc/contract@2036

@orpc/experimental-effect

npm i https://pkg.pr.new/@orpc/experimental-effect@2036

@orpc/evlog

npm i https://pkg.pr.new/@orpc/evlog@2036

@orpc/hibernation

npm i https://pkg.pr.new/@orpc/hibernation@2036

@orpc/json-schema

npm i https://pkg.pr.new/@orpc/json-schema@2036

@orpc/experimental-lock

npm i https://pkg.pr.new/@orpc/experimental-lock@2036

@orpc/experimental-msw

npm i https://pkg.pr.new/@orpc/experimental-msw@2036

@orpc/nest

npm i https://pkg.pr.new/@orpc/nest@2036

@orpc/next

npm i https://pkg.pr.new/@orpc/next@2036

@orpc/node

npm i https://pkg.pr.new/@orpc/node@2036

@orpc/openapi

npm i https://pkg.pr.new/@orpc/openapi@2036

@orpc/opentelemetry

npm i https://pkg.pr.new/@orpc/opentelemetry@2036

@orpc/pinia-colada

npm i https://pkg.pr.new/@orpc/pinia-colada@2036

@orpc/pino

npm i https://pkg.pr.new/@orpc/pino@2036

@orpc/publisher

npm i https://pkg.pr.new/@orpc/publisher@2036

@orpc/ratelimit

npm i https://pkg.pr.new/@orpc/ratelimit@2036

@orpc/server

npm i https://pkg.pr.new/@orpc/server@2036

@orpc/shared

npm i https://pkg.pr.new/@orpc/shared@2036

@orpc/swr

npm i https://pkg.pr.new/@orpc/swr@2036

@orpc/tanstack-query

npm i https://pkg.pr.new/@orpc/tanstack-query@2036

@orpc/trpc

npm i https://pkg.pr.new/@orpc/trpc@2036

@orpc/valibot

npm i https://pkg.pr.new/@orpc/valibot@2036

@orpc/zod

npm i https://pkg.pr.new/@orpc/zod@2036

commit: 97939fc

@codecov

codecov Bot commented Sep 17, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@codspeed

codspeed Bot commented Sep 17, 2026

Copy link
Copy Markdown
Contributor

Merging this PR will not alter performance

✅ 30 untouched benchmarks


Comparing dinwwwh:claude/cloudflare-worker-build-82d8b6 (97939fc) with main (1d8f9ba)

Open in CodSpeed

@dinwwwh
dinwwwh merged commit 8da683c into middleapi:main Sep 17, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant