Skip to content

build(deps): bump pnpm/setup from 2.1.0 to 3.0.0 - #893

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/pnpm/setup-3.0.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/pnpm/setup-3.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Bumps pnpm/setup from 2.1.0 to 3.0.0.

Release notes

Sourced from pnpm/setup's releases.

v3.0.0

What's Changed

New Contributors

Full Changelog: pnpm/setup@v2.1.0...v3.0.0

Commits
  • fbda4c8 docs(README): update version
  • c868a7d fix: require-lockfile no longer accepts a lockfile pnpm will not use (#60)
  • 463911b fix: avoid deprecated shell spawning for pnpm commands (#52)
  • 6598286 docs: add private registry authentication recipes (#61)
  • c5b2e24 feat!: automatically detect Node.js version files (#49)
  • f37adde fix!: include runid in cache key, restore freshest lockfile match (#43)
  • See full diff in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 28, 2026
@dependabot
dependabot Bot requested a review from qnbs as a code owner September 28, 2026 23:48
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 28, 2026
@vercel

vercel Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
worldscript-studio Ready Ready Preview Oct 3, 2026 4:54am UTC

@codeant-ai

codeant-ai Bot commented Sep 28, 2026

Copy link
Copy Markdown

Skipping PR review because a bot author is detected.

If you want to trigger CodeAnt AI, comment @codeant-ai review to trigger a manual review.

@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository: qnbs/WorldScript-Studio/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: cfa978f2-8546-4b30-b392-8713dbcba0a2

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@codeant-ai

codeant-ai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

🏁 CodeAnt Quality Gate Results

Commit: 14dc6f8e
Scan Time: 2026-10-03 04:54:07 UTC

✅ Overall Status: PASSED

Quality Gate Details

Quality Gate Status Details
Secrets ✅ PASSED 0 secrets found
Duplicate Code ✅ PASSED 0.0% duplicated
SAST ✅ PASSED No security issues
Bugs ✅ PASSED Rating S: No bugs
IAC ✅ PASSED Rating S: No issues

View Full Results

codescene-access[bot]

This comment was marked as outdated.

@codecov

codecov Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

❌ 1 Tests Failed:

Tests completed Failed Passed Skipped
9184 1 9183 0
View the top 1 failed test(s) by shortest run time
tests/unit/workflowPolicy.test.ts > CI workflow policy > bootstraps the exact secure pnpm in the workflow-policy job itself, before the gate it validates
Stack Traces | 0.0482s run time
AssertionError: expected '  workflow-policy:\n    name: 📜 Work…' to contain 'pnpm/setup@703c52620218391530e48b9e88…'

- Expected
+ Received

- pnpm/setup@703c52620218391530e48b9e8870d5c0082e1b9b
+   workflow-policy:
+     name: 📜 Workflow Policy Gate
+     runs-on: ubuntu-latest
+     timeout-minutes: 10
+     steps:
+       - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
+         with:
+           fetch-depth: 0
+           persist-credentials: false
+       # QNBS-v3: pnpm/setup instead of pnpm/action-setup, mirroring ..../actions/setup/action.yml (duplicated because this job predates the trust boundary it validates and can't use that composite).
+       - uses: pnpm/setup@fbda4c85fc2e1e08721cd8763afea8f48d60f024 # v3.0.0
+         with:
+           version: 11.22.0
+           install: false
+       - uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6.5.0
+         with:
+           node-version-file: .nvmrc
+           cache: pnpm
+       # QNBS-v3: no lifecycle/.pnpmfile.cjs hooks — install must not run repo code before the gate.
+       - name: Install dependencies (no lifecycle scripts)
+         run: pnpm install --frozen-lockfile --ignore-scripts --ignore-pnpmfile
+       # QNBS-v3: materialize the complete base workspace before governance; workspace:* packages and pinned patches are part of frozen resolution.
+       - name: Prepare trusted base governance workspace
+         if: github.event_name == 'pull_request'
+         env:
+           BASE_SHA: ${{ github.event.pull_request.base.sha }}
+         run: |
+           set -euo pipefail
+           if ! git cat-file -e "$BASE_SHA^{commit}"; then
+             echo "::error::base SHA is unavailable for trusted governance checks"
+             exit 1
+           fi
+           BASE_WORKSPACE="$(mktemp -d)"
+           git archive "$BASE_SHA" | tar -x -C "$BASE_WORKSPACE"
+           pnpm --dir "$BASE_WORKSPACE" install --frozen-lockfile --ignore-scripts --ignore-pnpmfile
+           echo "TRUSTED_BASE_WORKSPACE=$BASE_WORKSPACE" >> "$GITHUB_ENV"
+       # QNBS-v3: node directly — pnpm run's own pre-run check rejects an --ignore-pnpmfile install.
+       - name: Workflow-policy structural gate (permissions, needs graph, action pins)
+         run: |
+           set -euo pipefail
+           # QNBS-v3: PRs always run the trusted base checker; a missing base workspace fails via set -u instead of falling back to the PR copy.
+           if [ "$GITHUB_EVENT_NAME" = "pull_request" ]; then
+             WORKFLOW_POLICY_ROOT="${{ github.workspace }}" \
+               node "$TRUSTED_BASE_WORKSPACE/scripts/workflow-policy-check.mjs"
+           else
+             WORKFLOW_POLICY_ROOT="${{ github.workspace }}" \
+               node scripts/workflow-policy-check.mjs
+           fi
+       # QNBS-v3: use the trusted base checker for PRs; config and checker remain the PR workspace.
+       - name: Reviewer governance configuration gate
+         env:
+           BASE_SHA: ${{ github.event.pull_request.base.sha }}
+           REVIEWER_CONFIG_ROOT: ${{ github.workspace }}
+         run: |
+           set -euo pipefail
+           if [ "$GITHUB_EVENT_NAME" = "pull_request" ] && [ -n "${TRUSTED_BASE_WORKSPACE:-}" ] \
+              && [ -f "$TRUSTED_BASE_WORKSPACE/scripts/check-reviewer-config.mjs" ]; then
+             REVIEWER_CONFIG_ROOT="${{ github.workspace }}" \
+               REVIEWER_DEPENDENCY_ROOT="$TRUSTED_BASE_WORKSPACE" \
+               node "$TRUSTED_BASE_WORKSPACE/scripts/check-reviewer-config.mjs"
+           else
+             echo "::notice::base reviewer checker is absent (bootstrap); using the PR copy this one time."
+             node scripts/check-reviewer-config.mjs
+           fi
+
+   # ----------------------------------------------------------
+   # 0. SECURITY: pnpm audit + gitleaks + dependency review
+   # ----------------------------------------------------------

 ❯ tests/unit/workflowPolicy.test.ts:184:25

To view more test analytics, go to the Test Analytics Dashboard
📋 Got 3 mins? Take this short survey to help us improve Test Analytics.

codescene-access[bot]

This comment was marked as outdated.

@dependabot
dependabot Bot force-pushed the dependabot/github_actions/pnpm/setup-3.0.0 branch from de9bca4 to ad1c856 Compare September 29, 2026 07:52
codescene-access[bot]

This comment was marked as outdated.

@dependabot
dependabot Bot force-pushed the dependabot/github_actions/pnpm/setup-3.0.0 branch from ad1c856 to 592ed0e Compare September 29, 2026 08:19
codescene-access[bot]

This comment was marked as outdated.

@dependabot
dependabot Bot force-pushed the dependabot/github_actions/pnpm/setup-3.0.0 branch from 592ed0e to e83b164 Compare September 29, 2026 08:46
codescene-access[bot]

This comment was marked as outdated.

@dependabot
dependabot Bot force-pushed the dependabot/github_actions/pnpm/setup-3.0.0 branch from e83b164 to 2bcec99 Compare September 29, 2026 09:41
codescene-access[bot]

This comment was marked as outdated.

@qnbs

qnbs commented Sep 29, 2026

Copy link
Copy Markdown
Owner

Disposition for v1.29 (#872): BLOCKED_BY_INCOMPATIBILITY_OR_POLICY → post-release toolchain work.

@dependabot
dependabot Bot force-pushed the dependabot/github_actions/pnpm/setup-3.0.0 branch from 2bcec99 to 2ea720b Compare September 30, 2026 13:38
codescene-access[bot]

This comment was marked as outdated.

@dependabot
dependabot Bot force-pushed the dependabot/github_actions/pnpm/setup-3.0.0 branch from 2ea720b to 110464f Compare October 1, 2026 10:47
@deepsource-io

deepsource-io Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

DeepSource Code Review

We reviewed changes in 3cd2b6a...cc0db70 on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall Grade   Security  

Reliability  

Complexity  

Hygiene  

Code Review Summary

Analyzer Status Updated (UTC) Details
Docker Oct 3, 2026 4:53a.m. Review ↗
Python Oct 3, 2026 4:53a.m. Review ↗
Rust Oct 3, 2026 4:53a.m. Review ↗
Shell Oct 3, 2026 4:53a.m. Review ↗

Important

AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.

codescene-access[bot]

This comment was marked as outdated.

@dependabot
dependabot Bot force-pushed the dependabot/github_actions/pnpm/setup-3.0.0 branch from 110464f to 52ddcd6 Compare October 1, 2026 18:47
codescene-access[bot]

This comment was marked as outdated.

@dependabot
dependabot Bot force-pushed the dependabot/github_actions/pnpm/setup-3.0.0 branch from 52ddcd6 to 7937b25 Compare October 2, 2026 02:29
codescene-access[bot]

This comment was marked as outdated.

@dependabot
dependabot Bot force-pushed the dependabot/github_actions/pnpm/setup-3.0.0 branch from 7937b25 to 8beab7d Compare October 2, 2026 05:31
codescene-access[bot]

This comment was marked as outdated.

@dependabot
dependabot Bot force-pushed the dependabot/github_actions/pnpm/setup-3.0.0 branch from 8beab7d to 5749339 Compare October 2, 2026 06:58
codescene-access[bot]

This comment was marked as outdated.

@dependabot
dependabot Bot force-pushed the dependabot/github_actions/pnpm/setup-3.0.0 branch from 5749339 to 14dc6f8 Compare October 2, 2026 10:17
codescene-access[bot]

This comment was marked as outdated.

Bumps [pnpm/setup](https://github.com/pnpm/setup) from 2.1.0 to 3.0.0.
- [Release notes](https://github.com/pnpm/setup/releases)
- [Commits](pnpm/setup@703c526...fbda4c8)

---
updated-dependencies:
- dependency-name: pnpm/setup
  dependency-version: 3.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/pnpm/setup-3.0.0 branch from 14dc6f8 to cc0db70 Compare October 3, 2026 04:53

@codescene-access codescene-access Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No application code in the PR — skipped Code Health checks.

See analysis details in CodeScene

Quality Gate Profile: The Bare Minimum
Install CodeScene MCP: safeguard and uplift AI-generated code. Catch issues early with our IDE extension and CLI tool.

This branch was successfully deployed

1 active deployment
Preview — cc0db70a Deployed Oct 3, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant