| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
1 parent 3fa7265 commit bb35510
6 files changed
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -55,6 +55,9 @@ reviews: | |||
| 55 | 55 | This project uses pnpm only. Flag npm or yarn commands in scripts, | |
| 56 | 56 | docs, CI, and Dockerfiles. | |
| 57 | 57 | Keep functions small and single-purpose. | |
| 58 | + Never run package installs or commit pnpm-lock.yaml changes when | ||
| 59 | + applying fixes. Lockfiles change only together with a package.json | ||
| 60 | + change, made by a human with the pinned pnpm version. | ||
| 58 | 61 | ||
| 59 | 62 | - path: 'api/src/**/*.ts' | |
| 60 | 63 | instructions: | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -54,7 +54,7 @@ jobs: | |||
| 54 | 54 | - name: Install pnpm | |
| 55 | 55 | uses: pnpm/action-setup@v6 | |
| 56 | 56 | with: | |
| 57 | - version: 9 | ||
| 57 | + package_json_file: api/package.json | ||
| 58 | 58 | run_install: false | |
| 59 | 59 | ||
| 60 | 60 | - name: Set up Node.js | |
@@ -65,7 +65,7 @@ jobs: | |||
| 65 | 65 | cache-dependency-path: api/pnpm-lock.yaml | |
| 66 | 66 | ||
| 67 | 67 | - name: Install dependencies | |
| 68 | - run: pnpm install | ||
| 68 | + run: pnpm install --frozen-lockfile | ||
| 69 | 69 | ||
| 70 | 70 | - name: Build | |
| 71 | 71 | run: pnpm run build | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -0,0 +1,35 @@ | |||
| 1 | + # Fails any PR where a pnpm-lock.yaml changes without its sibling | ||
| 2 | + # package.json. A lockfile that moves on its own means someone (or some | ||
| 3 | + # bot) re-resolved dependencies wholesale, which is how PR #270 shipped a | ||
| 4 | + # broken zod major bump inside @polar-sh/sdk. See issue #271. | ||
| 5 | + name: Lockfile guard | ||
| 6 | + | ||
| 7 | + on: | ||
| 8 | + pull_request: | ||
| 9 | + paths: | ||
| 10 | + - '**/pnpm-lock.yaml' | ||
| 11 | + - '**/package.json' | ||
| 12 | + | ||
| 13 | + jobs: | ||
| 14 | + guard: | ||
| 15 | + name: Lockfile changes match a package.json change | ||
| 16 | + runs-on: ubuntu-latest | ||
| 17 | + steps: | ||
| 18 | + - name: Checkout repository | ||
| 19 | + uses: actions/checkout@v7 | ||
| 20 | + with: | ||
| 21 | + fetch-depth: 0 | ||
| 22 | + persist-credentials: false | ||
| 23 | + | ||
| 24 | + - name: Fail if a lockfile changed without its package.json | ||
| 25 | + run: | | ||
| 26 | + changed="$(git diff --name-only "origin/${{ github.base_ref }}"...HEAD)" | ||
| 27 | + failed=0 | ||
| 28 | + for app in api web; do | ||
| 29 | + if grep -qx "$app/pnpm-lock.yaml" <<<"$changed" \ | ||
| 30 | + && ! grep -qx "$app/package.json" <<<"$changed"; then | ||
| 31 | + echo "::error::$app/pnpm-lock.yaml changed without $app/package.json. Restore the lockfile, or include the package.json change that motivates it." | ||
| 32 | + failed=1 | ||
| 33 | + fi | ||
| 34 | + done | ||
| 35 | + exit "$failed" | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -53,7 +53,7 @@ jobs: | |||
| 53 | 53 | - name: Install pnpm | |
| 54 | 54 | uses: pnpm/action-setup@v6 | |
| 55 | 55 | with: | |
| 56 | - version: 9 | ||
| 56 | + package_json_file: web/package.json | ||
| 57 | 57 | run_install: false | |
| 58 | 58 | ||
| 59 | 59 | - name: Set up Node.js | |
@@ -64,7 +64,7 @@ jobs: | |||
| 64 | 64 | cache-dependency-path: web/pnpm-lock.yaml | |
| 65 | 65 | ||
| 66 | 66 | - name: Install dependencies | |
| 67 | - run: pnpm install | ||
| 67 | + run: pnpm install --frozen-lockfile | ||
| 68 | 68 | ||
| 69 | 69 | - name: Lint | |
| 70 | 70 | run: pnpm lint | |
@@ -105,7 +105,7 @@ jobs: | |||
| 105 | 105 | - name: Install pnpm | |
| 106 | 106 | uses: pnpm/action-setup@v6 | |
| 107 | 107 | with: | |
| 108 | - version: 9 | ||
| 108 | + package_json_file: web/package.json | ||
| 109 | 109 | run_install: false | |
| 110 | 110 | ||
| 111 | 111 | - name: Set up Node.js | |
@@ -116,7 +116,7 @@ jobs: | |||
| 116 | 116 | cache-dependency-path: web/pnpm-lock.yaml | |
| 117 | 117 | ||
| 118 | 118 | - name: Install dependencies | |
| 119 | - run: pnpm install | ||
| 119 | + run: pnpm install --frozen-lockfile | ||
| 120 | 120 | ||
| 121 | 121 | - name: Install Playwright browser | |
| 122 | 122 | run: pnpm exec playwright install --with-deps chromium | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -5,6 +5,7 @@ | |||
| 5 | 5 | "author": "", | |
| 6 | 6 | "private": true, | |
| 7 | 7 | "license": "UNLICENSED", | |
| 8 | + "packageManager": "pnpm@9.14.2", | ||
| 8 | 9 | "scripts": { | |
| 9 | 10 | "prebuild": "rimraf dist", | |
| 10 | 11 | "build": "nest build", | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -2,6 +2,7 @@ | |||
| 2 | 2 | "name": "textbee.dev", | |
| 3 | 3 | "version": "2.0.0", | |
| 4 | 4 | "private": true, | |
| 5 | + "packageManager": "pnpm@9.14.2", | ||
| 5 | 6 | "scripts": { | |
| 6 | 7 | "dev": "next dev", | |
| 7 | 8 | "build": "next build", | |
| Back | FazBrowse Home | New Git URL |
0 commit comments