FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

ci: guard pnpm lockfiles against wholesale regeneration · cperamsetty/SMS_textMessaging@bb35510 · GitHub

Commit bb35510

Browse files
andcommitted
ci: guard pnpm lockfiles against wholesale regeneration
CodeRabbit's auto-fix agent regenerated both lockfiles on PR textbee#270, floating zod to v4 inside @polar-sh/sdk and breaking the API build. Path filters already excluded lockfiles from review but do not stop the fix agent from committing whatever its sandbox produces. - lockfile-guard workflow fails any PR where a pnpm-lock.yaml changes without its sibling package.json - packageManager pins pnpm@9.14.2 in api and web, and CI reads the pin via package_json_file instead of a loose version: 9 - CI installs use --frozen-lockfile so an out-of-sync lockfile fails at install time instead of being silently re-resolved - .coderabbit.yaml instructs the fix agent to never run installs or commit lockfile changes Closes textbee#271 Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
1 parent 3fa7265 commit bb35510

6 files changed

Lines changed: 46 additions & 6 deletions

File tree

‎.coderabbit.yaml‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -55,6 +55,9 @@ reviews:
5555
This project uses pnpm only. Flag npm or yarn commands in scripts,
5656
docs, CI, and Dockerfiles.
5757
Keep functions small and single-purpose.
58+
Never run package installs or commit pnpm-lock.yaml changes when
59+
applying fixes. Lockfiles change only together with a package.json
60+
change, made by a human with the pinned pnpm version.
5861
5962
- path: 'api/src/**/*.ts'
6063
instructions: |

‎.github/workflows/api.yaml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -54,7 +54,7 @@ jobs:
5454
- name: Install pnpm
5555
uses: pnpm/action-setup@v6
5656
with:
57-
version: 9
57+
package_json_file: api/package.json
5858
run_install: false
5959

6060
- name: Set up Node.js
@@ -65,7 +65,7 @@ jobs:
6565
cache-dependency-path: api/pnpm-lock.yaml
6666

6767
- name: Install dependencies
68-
run: pnpm install
68+
run: pnpm install --frozen-lockfile
6969

7070
- name: Build
7171
run: pnpm run build
Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
# Fails any PR where a pnpm-lock.yaml changes without its sibling
2+
# package.json. A lockfile that moves on its own means someone (or some
3+
# bot) re-resolved dependencies wholesale, which is how PR #270 shipped a
4+
# broken zod major bump inside @polar-sh/sdk. See issue #271.
5+
name: Lockfile guard
6+
7+
on:
8+
pull_request:
9+
paths:
10+
- '**/pnpm-lock.yaml'
11+
- '**/package.json'
12+
13+
jobs:
14+
guard:
15+
name: Lockfile changes match a package.json change
16+
runs-on: ubuntu-latest
17+
steps:
18+
- name: Checkout repository
19+
uses: actions/checkout@v7
20+
with:
21+
fetch-depth: 0
22+
persist-credentials: false
23+
24+
- name: Fail if a lockfile changed without its package.json
25+
run: |
26+
changed="$(git diff --name-only "origin/${{ github.base_ref }}"...HEAD)"
27+
failed=0
28+
for app in api web; do
29+
if grep -qx "$app/pnpm-lock.yaml" <<<"$changed" \
30+
&& ! grep -qx "$app/package.json" <<<"$changed"; then
31+
echo "::error::$app/pnpm-lock.yaml changed without $app/package.json. Restore the lockfile, or include the package.json change that motivates it."
32+
failed=1
33+
fi
34+
done
35+
exit "$failed"

‎.github/workflows/web.yaml‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -53,7 +53,7 @@ jobs:
5353
- name: Install pnpm
5454
uses: pnpm/action-setup@v6
5555
with:
56-
version: 9
56+
package_json_file: web/package.json
5757
run_install: false
5858

5959
- name: Set up Node.js
@@ -64,7 +64,7 @@ jobs:
6464
cache-dependency-path: web/pnpm-lock.yaml
6565

6666
- name: Install dependencies
67-
run: pnpm install
67+
run: pnpm install --frozen-lockfile
6868

6969
- name: Lint
7070
run: pnpm lint
@@ -105,7 +105,7 @@ jobs:
105105
- name: Install pnpm
106106
uses: pnpm/action-setup@v6
107107
with:
108-
version: 9
108+
package_json_file: web/package.json
109109
run_install: false
110110

111111
- name: Set up Node.js
@@ -116,7 +116,7 @@ jobs:
116116
cache-dependency-path: web/pnpm-lock.yaml
117117

118118
- name: Install dependencies
119-
run: pnpm install
119+
run: pnpm install --frozen-lockfile
120120

121121
- name: Install Playwright browser
122122
run: pnpm exec playwright install --with-deps chromium

‎api/package.json‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,7 @@
55
"author": "",
66
"private": true,
77
"license": "UNLICENSED",
8+
"packageManager": "pnpm@9.14.2",
89
"scripts": {
910
"prebuild": "rimraf dist",
1011
"build": "nest build",

‎web/package.json‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,7 @@
22
"name": "textbee.dev",
33
"version": "2.0.0",
44
"private": true,
5+
"packageManager": "pnpm@9.14.2",
56
"scripts": {
67
"dev": "next dev",
78
"build": "next build",

0 commit comments

Comments
 (0)

Back | FazBrowse Home | New Git URL