fix(ci): declare yellowstone-grpc patch in package.json so frozen install resolves (Blocker A of #344) - #375
Merged
Merged
Conversation
…stall Root cause of ERR_PNPM_LOCKFILE_CONFIG_MISMATCH on all lockfile-touching Dependabot PRs (#374/#358/#357): the patch is declared only in pnpm-workspace.yaml (a pnpm-10-only settings location). Dependabot's updater pnpm cannot read it, so its lockfile regen rewrites the patchedDependencies section to a hash-only inline entry; pnpm 10's frozen check then rejects the mismatch against the declared config. Keep-and-declare: move the explicit declaration to package.json pnpm.patchedDependencies — the classic location read by pnpm 9, pnpm 10, and Dependabot — and drop it from pnpm-workspace.yaml. Verified locally (pnpm 10.34.5, CI's major): - pnpm install --frozen-lockfile green; patch applied (dist/esm markers) - full regen 'pnpm install --no-frozen-lockfile' leaves pnpm-lock.yaml byte-identical to main - patch still required: it creates the dist/esm type:module/type:commonjs markers upstream 4.0.2 lacks (sip-protocol#1077, tsx named-import fix)
Contributor
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Implements the KEEP-AND-DECLARE fix for Blocker A documented in #344 (Sep 22 comment). Does not merge any dependency bumps — it unblocks the 6-PR pass that starts after this merges.
Root cause (reproduced, deterministic)
pnpm install --frozen-lockfileon every lockfile-touching Dependabot branch fails:@triton-one/yellowstone-grpc@4.0.2patch only inpnpm-workspace.yaml— a settings location only pnpm 10 reads. CI/Docker pin pnpm 10, so main installs fine.path:), e.g. on build(deps): bump the minor-and-patch group across 1 directory with 33 updates #374:{hash, path}config. Reproduced locally with pnpm 10.34.5 onorigin/dependabot/npm_and_yarn/minor-and-patch-e6685aadf7.Change
KEEP-AND-DECLARE: move the explicit declaration into
package.json(pnpm.patchedDependencies) — the classic location read by pnpm 9, pnpm 10, and Dependabot — and remove it frompnpm-workspace.yaml. Two files, no lockfile change.Patch is still required — not dropped
Patch 3e07c9c (fixes sip-protocol#1077) adds
{"type":"module"}/{"type":"commonjs"}markers todist/esm/of the pinned@triton-one/yellowstone-grpc@4.0.2; without them tsx fails to resolve named ESM imports. The npm tarball is immutable and still lacks the markers (patch applies cleanly), so it cannot be obsolete.Verified locally (pnpm 10.34.5 — CI's major)
pnpm install --frozen-lockfile→ green; patch applied (dist/esm/package.json={"type":"module"}present innode_modules)pnpm install --no-frozen-lockfile→pnpm-lock.yamlbyte-identical to main (zero diff){hash,path}lockfile + either declaration site → green; hash-only lockfile → red at both declaration sitesWhat this fixes and what it doesn't
@dependabot rebaseforces a regen; worst case the lockfile gets the one-command hand regen per the standing playbook."packageManager": "pnpm@10…"so Dependabot/corepack provision pnpm 10 directly — happy to follow up if wanted.