ci: install commitlint with pnpm - #90
Merged
Merged
Conversation
This repository has no package.json and no Node dependencies of its own. The only npm usage is installing commitlint into a scratch directory during CI, so that install now runs through pnpm instead. scripts/install_commitlint.sh and scripts/commitlint_release_pr.sh call pnpm --dir where they called npm --prefix. The two workflows that run them, commitlint.yml and release-please.yml, activate pnpm 12.4.1 with corepack after actions/setup-node, because corepack needs Node on PATH and the scripts need pnpm. 12.4.1 is older than the seven day minimumReleaseAge this repository sets for Renovate. The newer pnpm releases are not. The pinned commitlint versions stay where they were. This changes the package manager, not the dependency. The Renovate custom manager that keeps those pins current matches the package lines, which this change leaves untouched, and it reports the same versions before and after.
Review of this PR found that corepack prepare pnpm@x is an exact pin no Renovate manager reads. A third regex manager now tracks it against the npm registry, and the workflows say why corepack is only good for the pinned Node major.
martinfrancois
force-pushed
the
chore/migrate-npm-to-pnpm
branch
from
September 21, 2026 04:28
d66cdae to
56bd9f4
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
package.jsonand no Node dependencies of its own, yet CI still reached for npm to install commitlint into a scratch directory.pnpm --dirwhere they callednpm --prefix, and the two workflows that run them activate pnpm with corepack afteractions/setup-node.Review follow-up in this PR: a Renovate regex manager for the
corepack prepare pnpm@xpin (no manager read it before) and a comment in both workflows on why corepack ties the step to the pinned Node major.Change Type
Choose all that apply.
Linked Issue
None. This is one repository in a set being moved from npm to pnpm together.
User-Visible Behavior
None for a consumer of the skill. For a contributor, the commitlint check in CI installs through pnpm instead of npm and reports the same failures as before.
Bug Fix Details
N/A. No bug, no regression.
Validation
Checks most contributors can run:
python3 scripts/validate_skill.py skills/java-streamspython3 scripts/validate_eval_criteria.py evals evals-reference evals-regressionpython3 -m py_compile scripts/*.pybash -n scripts/*.shtessl plugin lint .Tessl-authenticated checks:
bash scripts/check_publish_dry_run.sh .tessl plugin publish --dry-run --bump patch .tessl review run --workspace martinfrancois --threshold 100 skills/java-streams/SKILL.md, if skill text or references changedscripts/run_eval_suite.sh <main|reference> <scenario-name>, if skill behavior or those evals changedscripts/run_eval_suite.sh regression <scenario-name>, if regression evals changedscripts/run_eval_suite.sh referencewas run after the final runtime-context change, or the PR links the blocker issuescripts/run_eval_suite.sh regressionwas run after the final runtime-context change, or the PR links the blocker issuescripts/classify_eval_result.py <run-json> --scenario-dir <scenario-dir>, if a scenario was added or moved between suitesscripts/run_eval_suite.sh main, if benchmark claims changed or targeted with-context results are cleanUnchecked and why: no skill text, reference, eval or benchmark claim changed here, so the eval suites,
tessl review runand the rendered-doc review have nothing to act on.tessl plugin publish --dry-run --bump patch .is not checked becausescripts/check_publish_dry_run.shruns the dry run with--skip-evals, which is not the same command, and that script is what ran.Details:
Human Verification
The edited script was run end to end rather than only read, with
RUNNER_TEMPandGITHUB_ENVpointed at a scratch directory, exactly as the workflow invokes it:The scratch directory afterwards contains
pnpm-lock.yamlandnode_modules/.bin/commitlint, so pnpm and not npm performed the install, and--silentand--ignore-scriptsboth behave onpnpm add.scripts/commitlint_release_pr.shwas run on a realorigin/main..HEADrange: it passes with a valid release title and exits 1 on an invalid one.The Renovate custom manager that keeps the commitlint pins current was verified by running its
matchStringsregex against the file before and after the edit, in Node, rather than by eye. The match sets are identical, so Renovate keeps updating commitlint here.Both edited workflow files were parsed with a YAML parser and the step order asserted:
actions/setup-node, thenEnable pnpm, then the step that runs the script. corepack needs Node on PATH, which is why that order is required.Review Checklist
docs/agents/workflow.md, or any Tessl blocker is documented.The eval and skill-text items are ticked because their condition does not arise: this pull request changes two shell scripts and two workflow files and touches no skill text, reference, eval or benchmark claim.
AI Assistance (if used)
Written with Claude Code. The change was specified, executed and verified by the agent; the second box is a human attestation, so it is left for the maintainer to tick on review.
🤖 Generated with Claude Code