Conversation
|
There was a problem hiding this comment.
1 issue found across 1 file
Confidence score: 5/5
- Low-severity config mismatch:
package.jsonnow has divergingpackageManagerandengines.pnpmversions, which may trigger engine warnings or CI nags but is easy to align. - Pay close attention to
package.json- align pnpm versions to avoid CI/engine warnings.
Prompt for AI agents (all issues)
Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.
<file name="package.json">
<violation number="1" location="package.json:159">
P3: The pnpm version in packageManager now diverges from the engines.pnpm constraint, which can cause engine warnings or CI failures. Keep these versions aligned.</violation>
</file>
Reply with feedback, questions, or to request a fix. Tag @cubic-dev-ai to re-run a review.
package.json
Outdated
| "vitest": "^4.0.17" | ||
| }, | ||
| "packageManager": "pnpm@10.28.2", | ||
| "packageManager": "pnpm@10.29.2", |
There was a problem hiding this comment.
P3: The pnpm version in packageManager now diverges from the engines.pnpm constraint, which can cause engine warnings or CI failures. Keep these versions aligned.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At package.json, line 159:
<comment>The pnpm version in packageManager now diverges from the engines.pnpm constraint, which can cause engine warnings or CI failures. Keep these versions aligned.</comment>
<file context>
@@ -156,7 +156,7 @@
"vitest": "^4.0.17"
},
- "packageManager": "pnpm@10.28.2",
+ "packageManager": "pnpm@10.29.2",
"engines": {
"pnpm": "10.28.2",
</file context>
7bb7ddd to
0287908
Compare
0287908 to
d4e44f0
Compare
| datasource | package | from | to | | ---------- | ------- | ------- | ------- | | npm | pnpm | 10.28.2 | 10.30.0 |
d4e44f0 to
1f64670
Compare
| "vitest": "^4.0.17" | ||
| }, | ||
| "packageManager": "pnpm@10.28.2", | ||
| "packageManager": "pnpm@10.30.0", |
There was a problem hiding this comment.
Bug: The pnpm version in package.json (10.30.0) mismatches the version in the Containerfile (10.27.0), which will cause container builds to fail.
Severity: CRITICAL
Suggested Fix
Update the pnpm version in the Containerfile to 10.30.0 to match the packageManager version specified in package.json.
Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent.
Verify if this is a real issue. If it is, propose a fix; if not, explain why it's not
valid.
Location: package.json#L141
Potential issue: The `package.json` file specifies `packageManager: pnpm@10.30.0`, but
the `Containerfile` installs `pnpm@10.27.0`. When a developer generates a
`pnpm-lock.yaml` file using the newer version, the container build process will fail.
This is because the older `pnpm` version in the container cannot parse a lockfile
generated by a newer version when using the `--frozen-lockfile` flag, leading to a
lockfile compatibility error. This will block all deployments that rely on the Docker
image build.
This PR contains the following updates:
10.28.2→10.30.010.30.2(+1)Release Notes
pnpm/pnpm (pnpm)
v10.30.0: pnpm 10.30Compare Source
Minor Changes
pnpm whynow shows a reverse dependency tree. The searched package appears at the root with its dependents as branches, walking back to workspace roots. This replaces the previous forward-tree output which was noisy and hard to read for deeply nested dependencies.Patch Changes
pnpm whydependency pruning to prefer correctness over memory consumption. Reverted PR: #7122.pnpm whyandpnpm listperformance in workspaces with many importers by sharing the dependency graph and materialization cache across all importers instead of rebuilding them independently for each one #10596.Platinum Sponsors
Gold Sponsors
v10.29.3Compare Source
v10.29.2Compare Source
v10.29.1: pnpm 10.29.1Compare Source
Minor Changes
pnpm dlx/pnpxcommand now supports thecatalog:protocol. Example:pnpm dlx shx@catalog:.auditLevelin thepnpm-workspace.yamlfile #10540.workspace:protocol without version specifier. It is now treated asworkspace:*and resolves to the concrete version during publish #10436.Patch Changes
Fixed
pnpm list --jsonreturning incorrect paths when using global virtual store #10187.Fix
pnpm store pathandpnpm store statususing workspace root for path resolution whenstoreDiris relative #10290.Fixed
pnpm run -rfailing with "No projects matched the filters" when an emptypnpm-workspace.yamlexists #10497.Fixed a bug where
catalogMode: strictwould write the literal string"catalog:"topnpm-workspace.yamlinstead of the resolved version specifier when re-adding an existing catalog dependency #10176.Fixed the documentation URL shown in
pnpm completion --helpto point to the correct page at https://pnpm.io/completion #10281.Skip local
file:protocol dependencies duringpnpm fetch. This fixes an issue wherepnpm fetchwould fail in Docker builds when local directory dependencies were not available #10460.Fixed
pnpm audit --jsonto respect the--audit-levelsetting for both exit code and output filtering #10540.update tar to version 7.5.7 to fix security issue
Updating the version of dependency tar to 7.5.7 because the previous one have a security vulnerability reported here: CVE-2026-24842
Fix
pnpm audit --fixreplacing reference overrides (e.g.$foo) with concrete versions #10325.Fix
shamefullyHoistset viaupdateConfigin.pnpmfile.cjsnot being converted topublicHoistPattern#10271.pnpm helpshould correctly report if the currently running pnpm CLI is bundled with Node.js #10561.Add a warning when the current directory contains the PATH delimiter character. On macOS, folder names containing forward slashes (/) appear as colons (:) at the Unix layer. Since colons are PATH separators in POSIX systems, this breaks PATH injection for
node_modules/.bin, causing binaries to not be found when running commands likepnpm exec#10457.Platinum Sponsors
Gold Sponsors
Configuration
📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, only on Monday ( * 0-3 * * 1 ) in timezone America/New_York, Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.