Repository navigation
chore: move the SDK root to pnpm - #1458
jordividaller wants to merge 6 commits into
Conversation
|
Already up to date 📦 Bundle Size Report
Size Limits
Largest Files (Top 5)
View All Files (291 total)
✅ Bundle size check passed |
|
Already up to date 📊 Coverage Report⚪ Coverage unchanged
Detailed BreakdownLines Coverage
Statements Coverage
Functions Coverage
Branches Coverage
✅ Coverage check passed |
| if: steps.check_script.outputs.exists == 'true' | ||
| working-directory: base | ||
| run: npm run size -- --output ../out/base-bundle.json | ||
| run: pnpm run size --output ../out/base-bundle.json |
There was a problem hiding this comment.
Base size job uses parent workspace
Medium Severity
The base checkout lives in base/ under this PR's pnpm-workspace.yaml, but the workflow still runs pnpm run build and pnpm run size there after a possible npm ci. pnpm walks up to the parent workspace, so those steps can build or measure the current branch instead of the base ref.
Reviewed by Cursor Bugbot for commit 3944715. Configure here.
Pin pnpm 11.10.0 through packageManager, switch the root scripts to pnpm and replace package-lock.json with pnpm-lock.yaml (imported from the npm lockfile, so resolved versions are unchanged). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Enable Corepack before setup-node and install the root with pnpm install --frozen-lockfile. example/ keeps installing with npm. Base-branch jobs fall back to npm ci while the base still has a package-lock.json. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The root is installed with pnpm now; an accidental npm install at the root would otherwise recreate an untracked package-lock.json that is easy to commit by mistake. example/ still uses npm, so only the root file is ignored. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…-4975)
Vercel installs example/ with npm and pulls the SDK as a git dependency,
so npm clones the root, installs its dependencies and runs prepare.
- Without package-lock.json that nested install resolves from scratch,
which crashes npm before 11.6 ("Cannot read properties of null
(reading 'edgesOut')"). Vercel's Node 22 ships npm 10, so the install
command now runs a pinned npm 11.6.2.
- prepare goes back to npm run build so it works where pnpm is not
installed (npm git-dependency preparation); pnpm install still runs it.
- example/ sets an inline PostCSS config so Vite stops picking up the
root postcss.config.mjs, whose Tailwind plugin is not installed in the
example deploy. The example build output is unchanged.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
3944715 to
3fa0f89
Compare
|
Deploy preview for remote-flows ready!
Deployed with vercel-action |
|
Deploy preview for adp-cost-calculator ready!
Deployed with vercel-action |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
There are 2 total unresolved issues (including 1 from previous review).
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 3fa0f89. Configure here.
| if: steps.check_script.outputs.exists == 'true' | ||
| working-directory: base | ||
| run: npm run size -- --output ../out/base-bundle.json | ||
| run: pnpm run size --output ../out/base-bundle.json |
There was a problem hiding this comment.
Base jobs ignore npm fallback
Medium Severity
The base-branch install step switches to npm ci when pnpm-lock.yaml is missing, but the following build, size, coverage, and extract steps always run pnpm run. This PR’s base is still on npm, so those commands run against an npm-installed tree. In size-check.yml they also run inside base/ under the PR’s pnpm-workspace.yaml, so pnpm can pick up the parent workspace instead of the base package. Bundle-size and coverage comparison against main can fail or compare the wrong tree until the fallback is removed.
Additional Locations (1)
Reviewed by Cursor Bugbot for commit 3fa0f89. Configure here.
ce90bf9 to
3fa0f89
Compare


Summary
The SDK root now installs and runs with pnpm 11.10.0 instead of npm.
example/stays on npm for now. The code and the published JavaScript don't change. The Vercel deploys ofexample/keep working with the pnpm root.Why
This is step 1 of the pnpm migration. Step 0 (#1454) declared the phantom dependencies, so this PR changes the package manager, plus the minimum the Vercel deploys need to keep building. Moving
example/and Vercel to pnpm is the next step, docs the one after. Merging this PR on its own leavesmaindeployable: both Vercel previews build on it.Vercel. Vercel installs
example/with npm and pulls the SDK as agithub:dependency pinned to the commit. npm clones the root, runsnpm install --forcein it, then runsprepare. Two things broke once the root moved to pnpm:package-lock.jsonin the clone, that nested install resolves from scratch, and npm crashes on it before 11.6:Cannot read properties of null (reading 'edgesOut'), thengit dep preparation failed. The Remote Flows project builds on Node 22, which ships npm 10. I reproduced the exact error locally with npm 10.9.3, 11.0.0, 11.3.0 and 11.5.1; 11.6.2 installs and builds the SDK. The install command inexample/vercel.jsonnow runs a pinnednpm@11.6.2. npm passes its own binary to the nested install, so both use 11.6.2.preparecan't call pnpm, because pnpm isn't guaranteed to exist where npm prepares a git dependency. It staysnpm run build, as onmain.pnpm installruns it the same way.example/looked up the tree, found the rootpostcss.config.mjsand couldn't load@tailwindcss/postcss, which the example deploy never installs.example/doesn't use Tailwind or PostCSS (the SDK ships its CSS prebuilt), so its Vite config now sets an inline, empty PostCSS config. The example build output is byte-identical with and without it.No
preinstall: npx only-allow pnpmguard. The ticket asked for one. I tried it and dropped it, because the script ships in the publishedpackage.jsonand runs outside this repo:pnpm add @remoteoss/remote-flowsfails withERR_PNPM_IGNORED_BUILDS. pnpm 11 treats any dependency install script as a fatal unapproved build. I reproduced it with a packed test package; the same package withoutpreinstallinstalls fine.npx only-allow pnpm, so it downloads and runs a third-party package. That fails offline or behind a locked-down registry.cd example && npm installfails locally. npm runs thepreinstallof the linkedfile:..SDK, and only-allow sees npm. CI passes only because it installs with--ignore-scripts.preinstalltoo, and fails ("git dep preparation failed", reproduced with a local git dependency).The root pins pnpm through
packageManager, which Corepack enforces, and.gitignorenow ignores a rootpackage-lock.jsonso an accidentalnpm installat the root can't get committed.What changed
Toggle details
package.jsonpackageManager: pnpm@11.10.0.pnpm run ...(ci,check-exports,openapi-ts,openapi-ts:local,audit). They usepnpm runexplicitly becausepnpm ciis pnpm's own clean install and would never run ourciscript.preparestaysnpm run build(see Why).pnpm-lock.yamlreplacespackage-lock.json. I generated it withpnpm importfrom the npm lockfile, then ranpnpm installafter rebasing onmain(addsrandexp). A package-by-package comparison withmain'spackage-lock.jsonshows the same 631 packages at the same versions. The lockfile is generated, nothing to review in it..gitignore:/package-lock.json(root only,example/keeps its npm lockfile).pnpm-workspace.yamlonly holds settings, with nopackages:key, so the root andexample/stay independent projects. pnpm 11 makes unapproved build scripts fatal, soallowBuildslists the three that appear and skips them:@parcel/watcherandesbuildship their native binaries as per-platform optional dependencies, so their scripts are only checks or fallbacks.msw.workerDirectoryis set, and it isn't.example/vercel.json: the install command runsnpx --yes npm@11.6.2 install.example/vite.config.mts:css: { postcss: {} }.pr,ci-main,coverage,size-check,update-badge,release)corepack enableruns beforesetup-node, andsetup-nodeusescache: 'pnpm'.release.ymlgets no cache: it publishes, and it had no npm cache before either.pnpm install --frozen-lockfile --ignore-scripts. Path filters usepnpm-lock.yaml.pnpm run size --output ...replacesnpm run size -- --output ..., and the same forcoverage:extract.npm viewandnpm publishstay inrelease.ymlbecause they are registry operations.pr,ci-main,e2e-nightly) and the example checks install the root with pnpm.example/still installs withnpm ci. Without apackage-lock.json, the root couldn't stay onnpm ci.openapi-codegen-smoke-test.ymlwas not in the ticket's list, but it runsnpm ciat the root, so without apackage-lock.jsonit would fail. It is converted too.base-coverageinpr.yml, the base build insize-check.yml) usepnpm installwhen the base has apnpm-lock.yamlandnpm ciotherwise. This PR's base is still on npm. The fallback can go in a follow-up once this is merged.scripts/release.ts,release-hotfix.ts:pnpm run formatandpnpm install.scripts/create-worktree.tsinstalls the root withpnpm installandexample/withnpm install.scripts/seed-onboarding.ts: usage examples usepnpm run.renovate.json: addspnpmDedupenext tonpmDedupe.example/keeps its npm lockfile, so both are needed.mainbuild made with npm: every.jsfile is byte-identical. The.d.tsfiles reference declared dependencies instead of inlining copies of transitive types:@tanstack/react-queryinstead of an inlined@tanstack/query-corechunk (2.5k lines), andFieldsfrom@remoteoss/remote-json-schema-form-kitinstead of the kit's internal alias. The exported types are equivalent andcheck-exportspasses. Public API: no change..cursor/environment.json,.cursor/hooks/*,.cursor/rules/*,scripts/update-gist.sh, the.mddocs and the skills still mention npm.Screenshots
N/A
Related Resources
example/+ Vercel) and PBYR-4977 (docs).Testing
pnpm run ciis green: build, format, exports, lint, type-check and 1137 unit tests.example/:npm run lintandnpm run type-checkpass.vite buildoutput is byte-identical with and without the inline PostCSS config.Vercel install, reproduced locally: a copy of
example/package.json+ lockfile with the SDK as agit+file:dependency on this branch, and no pnpm onPATH. npm 10.9.3 fails with the sameedgesOuterror as the CI log;npm@11.6.2installs and builds the SDKdist/.Both Vercel previews (
Deploy Remote Flows Preview,Deploy Cost Calculator Preview) build on this PR.E2E (
example/, all browsers): 21 passed, 6 failed. The 6 failures areonboard-basic-employeeandonboard-germany-employee("Preview Employment Agreement" instead of "Review"). They fail the same way on amainbuild with the local test company.Tested against the
example/app in a browserFeature flag: N/A
🤖 Generated with Claude Code
Note
Medium Risk
Wide CI/release and install-path changes with no runtime code edits; misconfiguration could break builds or Vercel git-dependency installs until validated on main.
Overview
Migrates the SDK repo root from npm to pnpm (
packageManager,pnpm-lock.yaml, root scripts and lockfile path filters).example/remains on npm for installs in CI and locally; only the root usespnpm install --frozen-lockfileandpnpm runin workflows (with Corepack enabled and pnpm caching onsetup-node).CI and release automation are updated across pr, ci-main, coverage, size-check, release, etc., including fallback
npm cion base branches that still lackpnpm-lock.yaml.pnpm-workspace.yamlonly configuresallowBuilds(no workspace packages). Renovate addspnpmDedupe.Vercel / example deploy fixes:
example/vercel.jsonpinsnpm@11.6.2for installing the git-pinned SDK root;example/vite.config.mtssets an empty inline PostCSS config so the example build does not pick up the root Tailwind PostCSS setup. Root/package-lock.jsonis gitignored;preparestaysnpm run buildfor npm/git-dependency consumers.Helper scripts (release, worktree, seed-onboarding) and docs comments switch to pnpm at the root where applicable.
Reviewed by Cursor Bugbot for commit ce90bf9. Bugbot is set up for automated code reviews on this repo. Configure here.