Skip to content

chore(deps): pin pnpm 9.15.9 via packageManager; Dependabot skips maj… - #76

Merged
csupenn merged 1 commit into
devfrom
chore/pnpm-version-and-dependabot
Sep 28, 2026
Merged

csupenn merged 1 commit into
devfrom
chore/pnpm-version-and-dependabot

Conversation

@csupenn

@csupenn csupenn commented Sep 28, 2026

Copy link
Copy Markdown
Owner

…or bumps

Dependabot's npm PRs (#67-#71) all failed at pnpm install --frozen- lockfile with ERR_PNPM_LOCKFILE_CONFIG_MISMATCH: its regenerated lockfile dropped the overrides: section that package.json declares. The repo didn't declare its pnpm version, so Dependabot, CI (pnpm 9 via action-setup) and local installs (pnpm 10) disagreed.

  • package.json: "packageManager": "pnpm@9.15.9". pnpm 10 switches to it automatically for this project; Dependabot and Corepack read it.
  • CI: pnpm/action-setup@v6 takes the version from packageManager (setting both errors in v6).
  • dependabot.yml: ignore semver-major version updates (Next 16, AI SDK 7, framer-motion 13 need planned migrations). CI's critical-audit step still catches critical advisories.

Verified locally with the pinned pnpm: frozen install (lockfile unchanged), type-check, lint (0 errors), 850 tests, production build.

What and why

How it was verified

  • pnpm type-check and pnpm lint (0 errors)
  • pnpm test:ci (tests + coverage thresholds)
  • pnpm build, and affected pages checked on a local production build
  • Security fixes: a test that fails on the old code for the right reason, and passes now

Public claims (README, pages, blog, images, badges)

  • Every feature or number mentioned exists on main and is described at its real scope
  • Sample or demo data is labeled as such where people see it
  • No absolute security/compliance wording ("secure", "compliant", "sandboxed") without a scope
  • Images show nothing the product doesn't do
  • The public-claims guard passes (lib/__tests__/public-claims.test.ts)

Privacy and security

  • No user content, keys or IPs added to logs
  • New outbound requests go through the SSRF guard; new write endpoints check who is asking

…or bumps

Dependabot's npm PRs (#67-#71) all failed at `pnpm install --frozen-
lockfile` with ERR_PNPM_LOCKFILE_CONFIG_MISMATCH: its regenerated
lockfile dropped the `overrides:` section that package.json declares.
The repo didn't declare its pnpm version, so Dependabot, CI (pnpm 9 via
action-setup) and local installs (pnpm 10) disagreed.

- package.json: "packageManager": "pnpm@9.15.9". pnpm 10 switches to it
  automatically for this project; Dependabot and Corepack read it.
- CI: pnpm/action-setup@v6 takes the version from packageManager
  (setting both errors in v6).
- dependabot.yml: ignore semver-major version updates (Next 16, AI SDK 7,
  framer-motion 13 need planned migrations). CI's critical-audit step
  still catches critical advisories.

Verified locally with the pinned pnpm: frozen install (lockfile
unchanged), type-check, lint (0 errors), 850 tests, production build.
@vercel

vercel Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
top-flow Ready Ready Preview Sep 28, 2026 2:05am UTC

@csupenn
csupenn merged commit c402f0e into dev Sep 28, 2026
5 checks passed
@csupenn
csupenn deleted the chore/pnpm-version-and-dependabot branch September 28, 2026 02:11

This branch was successfully deployed

1 active deployment
Preview — 296c903e Deployed Sep 28, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant