-
Notifications
You must be signed in to change notification settings - Fork 36
ci: use pnpm/setup and devEngines
#797
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
4 commits
Select commit
Hold shift + click to select a range
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Oops, something went wrong.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win
🔎 Supported by static analysis
🏁 Script executed:
Repository: nuxt/module-builder
Length of output: 2139
🌐 Web query:
Node.js Corepack removed bundled Node.js 25 official documentation💡 Result:
Starting with Node.js v25.0.0, Corepack is no longer bundled with the official Node.js distribution [1][2]. This change was a result of a decision by the Node.js Technical Steering Committee (TSC) in March 2025 to phase out the distribution of Corepack within the Node.js core [3][4]. While Corepack was included with Node.js versions from v14.19.0 up to (but not including) v25.0.0, it is no longer present in the v25 release lines and beyond [1][2]. For users who require Corepack, it remains available as a package on npm [3]. To use it with Node.js v25 and later versions, you must install it globally using the following command [3][2]: npm install -g corepack Once installed via npm, Corepack functions similarly to how it did when bundled, though it does not require the
corepack enablestep that was necessary when using the version previously included with Node.js [3]. Existing projects or workflows that rely on the bundled version should be updated to account for this installation requirement [5][6][7].Citations:
🌐 Web query:
official npm devEngines packageManager onFail download documentation💡 Result:
The
devEnginesfield inpackage.jsonallows developers to specify required environments for a project, includingruntime,os,cpu,libc, andpackageManager[1][2]. Within this field, theonFailproperty defines the action taken when validation fails [1][2]. While the technical specification fordevEnginesdefines four possible values foronFail—ignore,warn,error, anddownload—npm has explicitly chosen not to implement thedownloadoption due to security concerns [3][2][4]. In the context of npm: -onFailsupportsignore,warn, anderror[1][5]. - IfonFailis left undefined, it defaults toerror[1][6]. - Thedownloadoption is not supported; if specified innpm, it will not trigger an automatic download of the required tool or version [3][4]. In contrast, other package managers (such as pnpm) may support thedownloadoption fordevEnginesto remediate validation failures by automatically fetching the necessary tool version [7]. For users relying on npm, environment requirements must be managed through explicit installation or alternative tools if strict version enforcement is required [3][4].Citations:
🌐 Web query:
site:pnpm.io/package_json devEngines onFail download packageManager pnpm💡 Result:
In pnpm, the devEngines configuration allows you to specify version requirements for runtimes and the package manager itself, with an onFail property to define behavior when the installed version does not meet the specified range [1]. For the packageManager, you can configure this in your package.json as follows [1]: { "devEngines": { "packageManager": { "name": "pnpm", "version": ">=11.0.0 <12.0.0", "onFail": "download" } } } When onFail is set to "download", pnpm will attempt to automatically download and use the version that satisfies the specified range if the current version does not match [1]. Key details include: - Version Ranges: Unlike the standard packageManager field, devEngines.packageManager supports version ranges [1]. - Lockfile Integration: The resolved version is stored in pnpm-lock.yaml under packageManagerDependencies and is reused as long as it continues to satisfy the defined range [1]. - Overrides: You can override the onFail behavior defined in the manifest by using the pmOnFail setting, which allows you to change the behavior without modifying the package.json file directly [1].
Citations:
Add a direct pnpm bootstrap for Node.js 25+ local setup.
devEngines.packageManager.onFail: "download"only runs after apnpmexecutable starts. It cannot bootstrap the firstpnpmcommand.README.mdstill requirescorepack enable, but Node.js 25+ does not bundle Corepack. Add a direct installation step forpnpm@12.3.4, or document that Node.js 25+ local setup is unsupported.🤖 Prompt for AI Agents
Source: MCP tools