diff --git a/package.json b/package.json index 4f46011..d0ebd1e 100644 --- a/package.json +++ b/package.json @@ -2,7 +2,7 @@ "name": "pgstencil-workspace", "private": true, "type": "module", - "packageManager": "pnpm@10.30.1", + "packageManager": "pnpm@12.4.1", "engines": { "node": ">=24" }, diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index 09718ff..adf0f20 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -1,3 +1,161 @@ +--- +lockfileVersion: '9.0' + +importers: + + .: + configDependencies: {} + packageManagerDependencies: + pnpm: + specifier: 12.4.1 + version: 12.4.1 + +packages: + + '@pnpm/exe.android-arm64@12.4.1': + resolution: {integrity: sha512-/HwsqXMSmlOfgtV9+O0ratzjV6Vd/8n1hh4rGHpCGmDURvt52MwZxdbhyxP4K03ZfvgSDvotFPr8O+RzE5Eu8A==} + cpu: [arm64] + os: [android] + + '@pnpm/exe.android-x64@12.4.1': + resolution: {integrity: sha512-+l74Qb4c2YjOzNKHXJLg+1wr8xHM1ckkUhnU5KRUK9TJqiiczt6yeTZqqzHIlJ8i6pAoj5V0OJevDRwnQKLgrQ==} + cpu: [x64] + os: [android] + + '@pnpm/exe.darwin-arm64@12.4.1': + resolution: {integrity: sha512-6rkZkT3iGfaxknUdGHraqSWFvTa6N0ajAHluv9Ax0GRWs0sIcGNiFhDopv6xSZCsJZmG483aNS/b6UEDy3blfw==} + cpu: [arm64] + os: [darwin] + + '@pnpm/exe.darwin-x64@12.4.1': + resolution: {integrity: sha512-Vb1CHlR88HghC1qUxjxjs82zQSXnXacPD+btG2CmG8Q/hBU7Q0/b2YWJKSQqZXicunV5khFtfTlAwJddV9RkYA==} + cpu: [x64] + os: [darwin] + + '@pnpm/exe.freebsd-x64@12.4.1': + resolution: {integrity: sha512-iT3iHz3Nl0Sxxj7UPOtZ/aQ81AFsQhjoeWMAlPkSRO04gsgDGAXv3UYxOFaesMWsfNxaGn0A+CITbuCHFF66FA==} + cpu: [x64] + os: [freebsd] + + '@pnpm/exe.linux-arm64-musl@12.4.1': + resolution: {integrity: sha512-aBooZfNXM5f+OGUgCAMFWpE/kAhsWfvmqIyMtHy6zl3aNxyInWrcY/Saln/UElzo7lZWMC0Yktroxd/2J26lNQ==} + cpu: [arm64] + os: [linux] + libc: [musl] + + '@pnpm/exe.linux-arm64@12.4.1': + resolution: {integrity: sha512-TlOdacTTP09BgcMvwWBFRsu8VAjfwqwnslBj+XSq1JFM3ck4f3k+1O/747EuctxZxs3/o785b6Q3s7Pd92Ptsg==} + cpu: [arm64] + os: [linux] + libc: [glibc] + + '@pnpm/exe.linux-ppc64@12.4.1': + resolution: {integrity: sha512-r/ab/MlIBo75oizUP5ITiziCCrnXz4SJwfErLQ+603AshB+Yq7xTMCoMtzTSCAMu6aaymIKkAFtZvd2J75Wq0w==} + cpu: [ppc64] + os: [linux] + libc: [glibc] + + '@pnpm/exe.linux-riscv64@12.4.1': + resolution: {integrity: sha512-C/D1QWdKMiB8+wv/spl1rGITFUuqC+aI/fb6h8NB5sqxsOaGXeYc/g891oCuzggHn6SODk9p+I09hI76x/cMNw==} + cpu: [riscv64] + os: [linux] + libc: [glibc] + + '@pnpm/exe.linux-s390x@12.4.1': + resolution: {integrity: sha512-nxz5zD4yXt94uzbStDk0QTPKW+aE92hH1b5tFXK9ctB1HE9Xcq1vjTiA2LsZMFC6p4gdu5OwQeFqYNAVGa6QlA==} + cpu: [s390x] + os: [linux] + libc: [glibc] + + '@pnpm/exe.linux-x64-musl@12.4.1': + resolution: {integrity: sha512-5AwgFdGhVUg2kIweYGfxzSLEHiIG77PQhZAkXC3TwofQHsu1Wr+TrV5/rNX2PopFnHRzuE581zoB8F6Wle32yg==} + cpu: [x64] + os: [linux] + libc: [musl] + + '@pnpm/exe.linux-x64@12.4.1': + resolution: {integrity: sha512-FJOZuuuQMhp0oLzBtcKkLXknBI92hfkmSnlKc47vfin4HrmfID5khY2lGekL9tCzk1cpR+HShEw/meFl+nHtzQ==} + cpu: [x64] + os: [linux] + libc: [glibc] + + '@pnpm/exe.win32-arm64@12.4.1': + resolution: {integrity: sha512-OO7eKBL9S+xk5hRy+JUUZSNJknGuGe3GEUffsrlC2LbqKF02g+VX1anGIzSbJDvkkdnpJhSlxF5AUz2JzJu2Jw==} + cpu: [arm64] + os: [win32] + + '@pnpm/exe.win32-x64@12.4.1': + resolution: {integrity: sha512-x7gJHZgHo6hp354xCYA2NvoFzYJkHwovt2kVsUBK5EmXULLcP51JGMq09CX+5FRFJUZFKoXjLu3mZWmfP7o6PQ==} + cpu: [x64] + os: [win32] + + pnpm@12.4.1: + resolution: {integrity: sha512-LoHjmdc/6DkNqyXgaqeIq3pZCCSNL1o3D4K0gRR6ano2e/gEj5pv22Rg8hpm8FQt7bi5TKLIcjWWdBkgsWVtTA==} + engines: {node: '>=18.*'} + hasBin: true + +snapshots: + + '@pnpm/exe.android-arm64@12.4.1': + optional: true + + '@pnpm/exe.android-x64@12.4.1': + optional: true + + '@pnpm/exe.darwin-arm64@12.4.1': + optional: true + + '@pnpm/exe.darwin-x64@12.4.1': + optional: true + + '@pnpm/exe.freebsd-x64@12.4.1': + optional: true + + '@pnpm/exe.linux-arm64-musl@12.4.1': + optional: true + + '@pnpm/exe.linux-arm64@12.4.1': + optional: true + + '@pnpm/exe.linux-ppc64@12.4.1': + optional: true + + '@pnpm/exe.linux-riscv64@12.4.1': + optional: true + + '@pnpm/exe.linux-s390x@12.4.1': + optional: true + + '@pnpm/exe.linux-x64-musl@12.4.1': + optional: true + + '@pnpm/exe.linux-x64@12.4.1': + optional: true + + '@pnpm/exe.win32-arm64@12.4.1': + optional: true + + '@pnpm/exe.win32-x64@12.4.1': + optional: true + + pnpm@12.4.1: + optionalDependencies: + '@pnpm/exe.android-arm64': 12.4.1 + '@pnpm/exe.android-x64': 12.4.1 + '@pnpm/exe.darwin-arm64': 12.4.1 + '@pnpm/exe.darwin-x64': 12.4.1 + '@pnpm/exe.freebsd-x64': 12.4.1 + '@pnpm/exe.linux-arm64': 12.4.1 + '@pnpm/exe.linux-arm64-musl': 12.4.1 + '@pnpm/exe.linux-ppc64': 12.4.1 + '@pnpm/exe.linux-riscv64': 12.4.1 + '@pnpm/exe.linux-s390x': 12.4.1 + '@pnpm/exe.linux-x64': 12.4.1 + '@pnpm/exe.linux-x64-musl': 12.4.1 + '@pnpm/exe.win32-arm64': 12.4.1 + '@pnpm/exe.win32-x64': 12.4.1 + +--- lockfileVersion: '9.0' settings: diff --git a/pnpm-workspace.yaml b/pnpm-workspace.yaml index da56c8c..d40b032 100644 --- a/pnpm-workspace.yaml +++ b/pnpm-workspace.yaml @@ -1,9 +1,12 @@ packages: - packages/* - examples/* -onlyBuiltDependencies: - - esbuild - - workerd +allowBuilds: + cpu-features: false + esbuild: true + protobufjs: false + ssh2: false + workerd: true # Ignore package versions published less than 1 day (1440 min) ago, so a # freshly published (possibly compromised or broken) release cannot enter an diff --git a/scripts/verify-packages.ts b/scripts/verify-packages.ts index b4c7e3c..c8a9621 100644 --- a/scripts/verify-packages.ts +++ b/scripts/verify-packages.ts @@ -6,6 +6,9 @@ import { projectRoot } from '../packages/pgstencil/src/paths.ts'; const directory = await mkdtemp(join(tmpdir(), 'pgstencil-packed-')); await mkdir(join(directory, 'vendor')); +const { packageManager } = JSON.parse( + await readFile(join(projectRoot, 'package.json'), 'utf8'), +) as { packageManager: string }; const dependencies: Record = {}; // The consumer owns every shared library, at the version this workspace tests. const peers: Record = {}; @@ -48,9 +51,8 @@ await writeFile( name: 'packed-consumer', private: true, type: 'module', - packageManager: 'pnpm@10.30.1', + packageManager, dependencies: { ...dependencies, ...peers }, - pnpm: { overrides: dependencies }, devDependencies: { '@types/node': '24.13.3', typescript: '5.9.3' }, }, null, @@ -72,10 +74,12 @@ import { billingMigrations } from '@pgstencil/stripe/migrations'; import { createStripeDev } from '@pgstencil/stripe/testing'; import { strict as assert } from 'node:assert'; import { readFileSync } from 'node:fs'; +const pgstencilVersion = JSON.parse(readFileSync(new URL('../package.json', import.meta.resolve('pgstencil')), 'utf8')).version; for (const name of ['pgstencil', '@pgstencil/auth', '@pgstencil/stripe']) { const entry = import.meta.resolve(name); const manifest = JSON.parse(readFileSync(new URL('../package.json', entry), 'utf8')); assert.equal(manifest.name, name); + if (name !== 'pgstencil') assert.equal(manifest.peerDependencies.pgstencil, '^' + pgstencilVersion); assert.equal(manifest.license, 'MIT'); assert.equal(manifest.repository.url, 'git+https://github.com/diffplug/pgstencil.git'); assert.ok(readFileSync(new URL('../LICENSE', entry), 'utf8').startsWith('MIT License')); @@ -134,10 +138,18 @@ await writeFile( }), ); // A shared library outside pgstencil's range, or one nothing provides, fails -// the install instead of only warning. +// the install instead of only warning. pnpm 12 reads these settings from the +// workspace file rather than package.json or .npmrc. await writeFile( - join(directory, '.npmrc'), - 'auto-install-peers=false\nstrict-peer-dependencies=true\n', + join(directory, 'pnpm-workspace.yaml'), + JSON.stringify({ + overrides: dependencies, + autoInstallPeers: false, + strictPeerDependencies: true, + // A file: tarball peer is reported by its path rather than its version. + // verify.ts checks the packed pgstencil peer range explicitly. + peerDependencyRules: { allowAny: ['pgstencil'] }, + }), ); execFileSync('pnpm', ['install', '--ignore-scripts'], { cwd: directory,