Skip to content

chore: manage dependencies with pnpm - #8

Merged
studiolxd merged 4 commits into
mainfrom
chore/pnpm
Sep 20, 2026
Merged

studiolxd merged 4 commits into
mainfrom
chore/pnpm

Conversation

@studiolxd

Copy link
Copy Markdown
Owner

Summary

Moves dependency management from npm to pnpm. Publishing is untouched: releases still go out with npm publish from packages/scorm, and the Angular smoke test still packs with npm pack, so it validates the exact artefact npm will publish.

The lockfile was produced with pnpm import, so every resolved version is inherited from package-lock.json rather than re-resolved. That was the precondition for the verification below to mean anything.

Verification

Check Result
Packed tarball vs. what is published on npmjs.com Identical sha256 (7ebcdd1d…), 49/49 files byte-identical
Build-critical dependency versions (tsup, esbuild, typescript, vitest, react, vue, svelte, @angular/core, …) 14/14 unchanged
example resolves the library symlink to packages/scorm, not the registry
Example bundle same content hash and size (index-Cg-LJ3UL.js, 332.33 kB) — rules out a duplicate React
Typecheck / tests clean / 419 passing
Angular AOT smoke against the packed tarball builds

Also removes three workarounds for npm defects

CI had accumulated them over the last few commits, and all three disappear here:

  • the npm/cli#4828 lockfile hack — package-lock.json was generated on macOS and lacked the installable entry for @rolldown/binding-linux-x64-gnu, so npm ci on Linux left vitest without its native binding;
  • npm's arborist crashing with Cannot read properties of null (reading 'edgesOut') on workspace installs;
  • the npm version pin those required.

pnpm records every platform variant in the lockfile and filters at install time.

Notes

  • tests/angular-smoke stays on npm and outside the workspace: it stands in for a real downstream consumer, and @angular-devkit/build-angular expects a flat node_modules.
  • example/package.json moves to workspace:*. With a plain *, pnpm resolved it to the published 2.0.1 from the registry instead of the local package — a silent failure that would have meant building the demo against stale code. example/vercel.json had to migrate in the same commit, since its npm install cannot parse the workspace: protocol.
  • package-lock.json is deleted in its own isolated commit, so reverting just that commit restores it intact.

Test plan

  • CI passes on Node 20 and 22
  • angular-smoke passes
  • Vercel preview opens and works in the browser — a duplicate React only shows at runtime

🤖 Generated with Claude Code

https://claude.ai/code/session_011kohSPc6KNpFd9EiV8Vbez

studiolxd and others added 3 commits September 20, 2026 11:32
Replaces npm with pnpm for dependency management across the monorepo. Publishing
is untouched: releases still go out with `npm publish` from packages/<lib>, and
the Angular smoke test still packs with `npm pack` so it validates the exact
artefact npm will publish.

The lockfile was produced with `pnpm import`, so every resolved version is
inherited from package-lock.json rather than re-resolved. Verified: the packed
tarball is byte-identical to what is published on npmjs.com (same sha256 for
scorm; for xapi the only delta is the newly declared rxjs devDependency), the
example bundles keep the same content hash and size, and the Angular AOT smoke
test still builds against the packed tarball.

This also removes three workarounds for npm defects that CI had accumulated:
the npm/cli#4828 lockfile hack (a macOS-generated lockfile made npm skip the
Linux rollup binary), the arborist `edgesOut` crash on workspace installs, and
the npm version pin those required. pnpm records every platform variant in the
lockfile and filters at install time.

tests/angular-smoke stays on npm and outside the workspace: it stands in for a
real downstream consumer, and @angular-devkit/build-angular expects a flat
node_modules.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011kohSPc6KNpFd9EiV8Vbez
Isolated on purpose: reverting this single commit restores the npm lockfile
intact if the pnpm migration needs to be rolled back.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011kohSPc6KNpFd9EiV8Vbez
Only development commands change. Installing the published package and releasing
it stay on npm, so `npm install @studiolxd/...` in the package READMEs and the
`npm publish` release steps are left alone.

Also documents why tests/angular-smoke stays on npm and outside the workspace,
and warns about the leftover-tarball trap in its manual run instructions.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011kohSPc6KNpFd9EiV8Vbez
@vercel

vercel Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
scorm-example Ready Ready Preview Sep 20, 2026 9:35am UTC

pnpm 11 requires Node >= 22.13, so the Node 20 matrix entry could not even start
it. GitHub is deprecating Node 20 on its runners anyway, and Node 20 reached end
of life earlier this year.

This only affects the build environment; the published package declares no
engines constraint and its output does not depend on the Node version that built
it (verified: the tarball built locally on Node 26 is byte-identical to the one
published from an older toolchain).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011kohSPc6KNpFd9EiV8Vbez
@studiolxd
studiolxd merged commit 671ac9c into main Sep 20, 2026
5 checks passed
@studiolxd
studiolxd deleted the chore/pnpm branch September 20, 2026 09:46

This branch was successfully deployed

1 active deployment
Preview — 0ffe50ac Deployed Sep 20, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant