Skip to content

update pnpm min release - #14

Open
spentacular wants to merge 1 commit into
mainfrom
pnpm-min-release
Open

spentacular wants to merge 1 commit into
mainfrom
pnpm-min-release

Conversation

@spentacular

@spentacular spentacular commented Sep 24, 2026 •

Copy link
Copy Markdown
Member

What's changing

Adds a minimum release age gate to pnpm-workspace.yaml so newly published versions of third-party dependencies aren't resolved until they've been on the registry for a while:

minimumReleaseAge: 4320 # 3 days
minimumReleaseAgeExclude:
  - "@player-cli/*"
  - "@player-lang/*"
  - "@xlr-lib/*"

Why

minimumReleaseAge is pnpm's mitigation for npm supply-chain attacks. Compromised package versions are typically published, detected, and unpublished/patched within hours — so refusing to install anything younger than a cooldown window means the malicious version is usually gone before we'd ever resolve it. This is the same class of defense that blunted the recent Shai-Hulud-style campaigns.

4320 minutes (3 days) is a deliberately conservative window — longer than pnpm 11's 24-hour default, since this repo's dependency updates aren't time-sensitive.

The three excluded scopes are our own first-party packages (@player-cli/*, @player-lang/*, @xlr-lib/*). Without the exclusion, every Player release would sit behind a 3-day wait before this repo could consume it, which would make canary and next verification impractical. minimumReleaseAgeExclude supports glob patterns as of pnpm v10.17.0.

Notes for reviewers

Two things worth confirming before merge — neither is addressed by this diff:

  1. pnpm version. package.json pins packageManager: [email protected] (and engines.pnpm: ^10.13.1). minimumReleaseAge / minimumReleaseAgeExclude were introduced in pnpm v10.16.0, and glob support in the exclude list landed in v10.17.0. On 10.13.1 these keys are simply unknown settings, so the gate won't take effect until the pinned pnpm is bumped to at least v10.17.0.

  2. pnpm-workspace.yaml is generated. The file's header says it's auto-generated by scripts/generate-pnpm-workspace.js, and that script writes the whole file from a template containing only the packages: list — so running it would silently drop these new settings. Nothing in CI, Bazel, or package.json currently invokes it, so this is latent rather than broken, but the script should either be taught to preserve these keys or removed.

Also note dependencies in CI are materialized by rules_js npm_translate_lock from pnpm-lock.yaml, so this setting governs resolution at lockfile-update time (local pnpm install / pnpm update), not the Bazel fetch of an already-pinned lockfile.

Relevant PNPM docs

Change Type (required)

Indicate the type of change your pull request is:

  • patch
  • minor
  • major

@spentacular
spentacular requested a review from a team as a code owner September 24, 2026 07:09
@codecov

codecov Bot commented Sep 24, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 35.88%. Comparing base (9aa1908) to head (72a6dfe).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main      #14   +/-   ##
=======================================
  Coverage   35.88%   35.88%           
=======================================
  Files          27       27           
  Lines        1956     1956           
  Branches      159      159           
=======================================
  Hits          702      702           
  Misses       1252     1252           
  Partials        2        2           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants