[E00-S01-T07] Commit and lock in pnpm 11.23.0 workspace #374
No Reviewers
Labels
Clear labels
agent/analyst-drafted
agent/analyst-drafted
needs/human-decision
needs/human-decision
needs/security-review
needs/security-review
tier/t0
tier/t1
tier/t2
tier/t3
kind
bug
kind
bug
kind
epic
kind
epic
kind
initiative
EPPP programme initiative
kind
story
kind
story
kind
task
EPPP engineering card/task decomposed from a story
kind
toil
kind
toil
loop
1
loop
1
loop
2
loop
2
loop
3
loop
3
risk
agent-full
risk
agent-full
risk
human-gated
risk
human-gated
risk
human-only
risk
human-only
size
l
size
l
size
m
size
m
size
s
size
s
status
blocked
status
blocked
status
done
Workflow: Done
status
in-progress
status
in-progress
status
proposed
status
proposed
status
ready
status
ready
status
review
status
review
stream
checkout
stream
checkout
stream
onboarding
stream
onboarding
stream
platform
stream
platform
trivial — implementer only, auto-merge
standard — implementer + reviewer + tester
complex — security if triggered, human merge
critical — full chain + security, human merge
No labels
Milestone
No items
No Milestone
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: Fabrika/PersonalBlog#374
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
What changed
Locks in the committed pnpm 11.23.0 workspace configuration for [E00-S01-T07] pnpm 11.23.0 workspace committed (#160). The workspace itself was bootstrap-committed in E00-S01-T01 (root
package.jsonpins"packageManager": "pnpm@11.23.0",pnpm-workspace.yamlgroupsapps/*,packages/*,extensions/*, frozenpnpm-lock.yamlgenerated by pnpm 11.23.0, CI wiring through corepack); this PR adds the regression suite that makes those acceptance criteria enforceable rather than incidental:tests/workspace-config.test.mjs(new) — anode:testsuite (zero dependencies, lockfile untouched) that fails if the committed workspace ever drifts:package.jsonpinspackageManagertopnpm@11.23.0(asserts the exact string)pnpm-workspace.yamlis committed and declares all three package groupspnpm-lock.yamlis committed with lockfile version9.0(the pnpm 11.23.0 format)pnpm-lock.yamlhas an importer for every workspace package (root +apps/server+packages/core+extensions/example)corepack pnpm --versionresolves 11.23.0 — install uses the committed pnpm version end-to-end--frozen-lockfileExplicitly out of scope per the brief (not touched): Node engine restriction (E00-S01-T08), TypeScript exact dependency (E00-S01-T09), strict base tsconfig (E00-S01-T10). No CI workflow changes — CI pipeline wiring of the test suite is E00-S05 by design (same as T05/T06).
Criterion → test table
tests/workspace-config.test.mjs: "root package.json pins packageManager to pnpm@11.23.0", "pnpm-workspace.yaml is committed and declares the three workspace groups", "pnpm-lock.yaml is committed with lockfile version 9.0", "pnpm-lock.yaml has an importer for every workspace package" — all fail if the pin/workspace/lockfile is missing, wrong or uncommittedtests/workspace-config.test.mjs: "corepack resolves the committed pnpm version (11.23.0)" — spawnscorepack pnpm --versionand asserts11.23.0; plus "committed CI workflow enables corepack and installs with the frozen lockfile". Mutation-probed: changing the pin topnpm@11.22.0fails both testsTest plan executed
node_modules):pnpm install --frozen-lockfilevia corepack → success,using pnpm v11.23.0, lockfile unchanged ✓pnpm test→ 16/16 pass (10 existing architecture-import tests + 6 new workspace-config tests), exit 0 ✓packageManagertemporarily set topnpm@11.22.0, the pin assertion and the corepack version resolution test both fail (not ok 1,not ok 5) — restoring the committed value returns to 16/16 ✓corepack pnpm --version→11.23.0(install resolves the committed version) ✓pnpm install --frozen-lockfileandpnpm -r list --depth -1(the two CI steps) both exit 0 from a clean checkout ✓Risks / notes
pnpm@11.23.0; a deliberate pnpm upgrade is a separate task and must update this test in the same change.corepackon PATH (it ships with Node ≥ 22 / CI Node 24); it spawns a version query only, no install, and stays under a 60s timeout.Refs #160