chore(deps): use pnpm default minimumReleaseAge - #457
Merged
Merged
Conversation
intent(pnpm-config): rely on pnpm defaults for release maturity instead of an explicit 3-day wait decision(pnpm-config): drop the setting entirely so both the wait (1440 minutes) and the non-strict mode follow pnpm defaults rejected(pnpm-config): minimumReleaseAge: 1440 to keep strict mode — the goal is to follow pnpm defaults, not pin a value learned(pnpm): pnpm 12 enables minimumReleaseAgeStrict by default only when minimumReleaseAge is explicitly set; the built-in default falls back to immature versions when no mature one satisfies the range Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
目的
pnpm がインストールする版の公開からの経過時間の条件を、リポジトリで明示せず pnpm の既定値に任せる。
lefthook 2.1.15 は provenance なしで npm に公開されたため、
trustPolicy: no-downgradeに止められ #456 が失敗している。provenance 付きの 2.1.16 が 2026-10-01 に公開されたが、明示している 3 日のminimumReleaseAgeのため pnpm がまだ解決できない。待つ期間は pnpm の既定値で足りると判断した。変更内容
pnpm-workspace.yamlからminimumReleaseAge: 4320を削除するpnpm installで lockfile に差分は出ない設計判断
minimumReleaseAge: 1440と値を明示する形は採らない。目的は値を選ぶことではなく pnpm の既定値に従うことであり、明示すると pnpm が既定値を変えても追従しない。挙動の変化
pnpm/crates/config/src/settings.rsのminimum_release_ageがSome(24 * 60))。合意事項によるminimumReleaseAgeを明示したときだけ strict を既定で有効にする(resolved_minimum_release_age_strictがexplicit_settingsにminimumReleaseAgeがあるかで決める)。設定を外すと既定値の非 strict になる。合意事項による。失われる旧実装の性質: 固定版で指定した公開直後の版を pnpm が拒否すること合意事項
minimumReleaseAgeの待つ時間と strict の有無はどちらも pnpm の既定値に任せるtrustPolicy: no-downgradeなどの他の設定は残す未合意の判断
なし
スコープ外
config:best-practicesがsecurity:minimumReleaseAgeNpm(npm に 3 日、internalChecksFilter: 'strict')を含むため、Renovate は npm の版を 3 日待ってから PR を作る。pnpm 側の 1 日とは揃わない。lefthook 2.1.16 の Renovate PR は 2026-10-04 以降に作られる。行き先: 揃える必要が生じたときに renovate.json で扱う完了条件
pnpm-workspace.yamlにminimumReleaseAgeが無い検証
mise.tomlで指定)の既定値を pnpm/pnpm のv12.8.1タグのソースで確認した:pnpm/crates/config/src/settings.rsの#[default(_code = "Some(24 * 60)")]pnpm installを pnpm v12.8.1 で実行し、git statusで lockfile に差分が無いことを確認した確認事項
なし
🤖 Generated with Claude Code