Repository navigation
chore: pin pnpm to exact version 12.4.2 - #2036
Conversation
There was a problem hiding this comment.
✅ No new issues found.
Reviewed changes
- Pin pnpm to exact
12.4.2inpackage.json:9— replaces the^12.4.1range so Corepack resolves a deterministic version instead of always fetching the newest 12.x. - Refresh
pnpm-lock.yaml—packageManagerDependencies.pnpmand everypnpm/@pnpm/exe.*package + snapshot entry move to12.4.2, with no12.4.1references left behind.
Verified the pnpm@12.4.2 and @pnpm/exe.linux-x64@12.4.2 integrity hashes against the npm registry (exact match), and confirmed the cited Corepack mechanism — nodejs/corepack#892, shipped in 0.36.0 — does resolve a devEngines range to the newest matching release, so the exact pin is what makes Corepack deterministic. pnpm/action-setup@v6 (CI passes no version input) handles an exact devEngines version fine, and there is no competing packageManager field. No minimumReleaseAge gate is actually configured, so the release's age is not a concern.
DeepSeek Flash (free via Pullfrog for OSS) | 𝕏
More templates
@orpc/ai-sdk
@orpc/arktype
@orpc/bun
@orpc/client
@orpc/cloudflare
@orpc/contract
@orpc/experimental-effect
@orpc/evlog
@orpc/hibernation
@orpc/json-schema
@orpc/experimental-lock
@orpc/experimental-msw
@orpc/nest
@orpc/next
@orpc/node
@orpc/openapi
@orpc/opentelemetry
@orpc/pinia-colada
@orpc/pino
@orpc/publisher
@orpc/ratelimit
@orpc/server
@orpc/shared
@orpc/swr
@orpc/tanstack-query
@orpc/trpc
@orpc/valibot
@orpc/zod
commit: |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |

Pins pnpm to exactly 12.4.2 in
devEngines.packageManagerinstead of the^12.4.1range, and records 12.4.2 inpnpm-lock.yaml. This unblocks the docs deploy and stops future pnpm releases from breaking it. Cloudflare Workers Builds runs pnpm through Corepack, which since 0.36.0 (nodejs/corepack#892) resolves adevEnginesrange to the newest pnpm on npm, and pnpm does not switch to the lockfile's version when Corepack starts it. Every new 12.x release (12.4.2 came out on September 15) therefore failedpnpm install --frozen-lockfilewithERR_PNPM_FROZEN_LOCKFILE_WITH_OUTDATED_LOCKFILEuntil the lockfile was refreshed.Behavior
devEngines.packageManager.version, then runpnpm install --lockfile-only.packageManagerDependenciesblock and thepnpm/@pnpm/exe.*entries.Testing
CI=trueand cold caches,pnpm install --frozen-lockfilereproduces the deploy error onmainand passes on this branch with pnpm 12.4.2.eslintandsherifpass.