Skip to content

chore: move the SDK root to pnpm - #1458

Open
jordividaller wants to merge 6 commits into
mainfrom
chore/pbyr-4975-move-sdk-root-to-pnpm
Open

jordividaller wants to merge 6 commits into
mainfrom
chore/pbyr-4975-move-sdk-root-to-pnpm

Conversation

@jordividaller

@jordividaller jordividaller commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

The SDK root now installs and runs with pnpm 11.10.0 instead of npm. example/ stays on npm for now. The code and the published JavaScript don't change. The Vercel deploys of example/ keep working with the pnpm root.

Why

This is step 1 of the pnpm migration. Step 0 (#1454) declared the phantom dependencies, so this PR changes the package manager, plus the minimum the Vercel deploys need to keep building. Moving example/ and Vercel to pnpm is the next step, docs the one after. Merging this PR on its own leaves main deployable: both Vercel previews build on it.

Vercel. Vercel installs example/ with npm and pulls the SDK as a github: dependency pinned to the commit. npm clones the root, runs npm install --force in it, then runs prepare. Two things broke once the root moved to pnpm:

  • With no package-lock.json in the clone, that nested install resolves from scratch, and npm crashes on it before 11.6: Cannot read properties of null (reading 'edgesOut'), then git dep preparation failed. The Remote Flows project builds on Node 22, which ships npm 10. I reproduced the exact error locally with npm 10.9.3, 11.0.0, 11.3.0 and 11.5.1; 11.6.2 installs and builds the SDK. The install command in example/vercel.json now runs a pinned npm@11.6.2. npm passes its own binary to the nested install, so both use 11.6.2.
  • prepare can't call pnpm, because pnpm isn't guaranteed to exist where npm prepares a git dependency. It stays npm run build, as on main. pnpm install runs it the same way.
  • The Cost Calculator build also failed: Vite in example/ looked up the tree, found the root postcss.config.mjs and couldn't load @tailwindcss/postcss, which the example deploy never installs. example/ doesn't use Tailwind or PostCSS (the SDK ships its CSS prebuilt), so its Vite config now sets an inline, empty PostCSS config. The example build output is byte-identical with and without it.

No preinstall: npx only-allow pnpm guard. The ticket asked for one. I tried it and dropped it, because the script ships in the published package.json and runs outside this repo:

  • pnpm 11 consumers: pnpm add @remoteoss/remote-flows fails with ERR_PNPM_IGNORED_BUILDS. pnpm 11 treats any dependency install script as a fatal unapproved build. I reproduced it with a packed test package; the same package without preinstall installs fine.
  • npm consumers: every install runs npx only-allow pnpm, so it downloads and runs a third-party package. That fails offline or behind a locked-down registry.
  • cd example && npm install fails locally. npm runs the preinstall of the linked file:.. SDK, and only-allow sees npm. CI passes only because it installs with --ignore-scripts.
  • Vercel's git dependency preparation runs preinstall too, and fails ("git dep preparation failed", reproduced with a local git dependency).

The root pins pnpm through packageManager, which Corepack enforces, and .gitignore now ignores a root package-lock.json so an accidental npm install at the root can't get committed.

What changed

Toggle details
  • package.json
    • packageManager: pnpm@11.10.0.
    • Scripts call pnpm run ... (ci, check-exports, openapi-ts, openapi-ts:local, audit). They use pnpm run explicitly because pnpm ci is pnpm's own clean install and would never run our ci script. prepare stays npm run build (see Why).
  • pnpm-lock.yaml replaces package-lock.json. I generated it with pnpm import from the npm lockfile, then ran pnpm install after rebasing on main (adds randexp). A package-by-package comparison with main's package-lock.json shows the same 631 packages at the same versions. The lockfile is generated, nothing to review in it.
  • .gitignore: /package-lock.json (root only, example/ keeps its npm lockfile).
  • pnpm-workspace.yaml only holds settings, with no packages: key, so the root and example/ stay independent projects. pnpm 11 makes unapproved build scripts fatal, so allowBuilds lists the three that appear and skips them:
    • @parcel/watcher and esbuild ship their native binaries as per-platform optional dependencies, so their scripts are only checks or fallbacks.
    • msw's postinstall only copies the browser worker when msw.workerDirectory is set, and it isn't.
  • example/vercel.json: the install command runs npx --yes npm@11.6.2 install. example/vite.config.mts: css: { postcss: {} }.
  • Workflows (pr, ci-main, coverage, size-check, update-badge, release)
    • corepack enable runs before setup-node, and setup-node uses cache: 'pnpm'. release.yml gets no cache: it publishes, and it had no npm cache before either.
    • The root installs with pnpm install --frozen-lockfile --ignore-scripts. Path filters use pnpm-lock.yaml.
    • pnpm run size --output ... replaces npm run size -- --output ..., and the same for coverage:extract.
    • npm view and npm publish stay in release.yml because they are registry operations.
  • The e2e jobs (pr, ci-main, e2e-nightly) and the example checks install the root with pnpm. example/ still installs with npm ci. Without a package-lock.json, the root couldn't stay on npm ci.
  • openapi-codegen-smoke-test.yml was not in the ticket's list, but it runs npm ci at the root, so without a package-lock.json it would fail. It is converted too.
  • Base-branch jobs (base-coverage in pr.yml, the base build in size-check.yml) use pnpm install when the base has a pnpm-lock.yaml and npm ci otherwise. This PR's base is still on npm. The fallback can go in a follow-up once this is merged.
  • scripts/release.ts, release-hotfix.ts: pnpm run format and pnpm install. scripts/create-worktree.ts installs the root with pnpm install and example/ with npm install. scripts/seed-onboarding.ts: usage examples use pnpm run.
  • renovate.json: adds pnpmDedupe next to npmDedupe. example/ keeps its npm lockfile, so both are needed.
  • Build output compared with a main build made with npm: every .js file is byte-identical. The .d.ts files reference declared dependencies instead of inlining copies of transitive types: @tanstack/react-query instead of an inlined @tanstack/query-core chunk (2.5k lines), and Fields from @remoteoss/remote-json-schema-form-kit instead of the kit's internal alias. The exported types are equivalent and check-exports passes. Public API: no change.
  • Left for the docs/tooling step: .cursor/environment.json, .cursor/hooks/*, .cursor/rules/*, scripts/update-gist.sh, the .md docs and the skills still mention npm.

Screenshots

N/A

Related Resources

Testing

  • pnpm run ci is green: build, format, exports, lint, type-check and 1137 unit tests.

  • example/: npm run lint and npm run type-check pass. vite build output is byte-identical with and without the inline PostCSS config.

  • Vercel install, reproduced locally: a copy of example/package.json + lockfile with the SDK as a git+file: dependency on this branch, and no pnpm on PATH. npm 10.9.3 fails with the same edgesOut error as the CI log; npm@11.6.2 installs and builds the SDK dist/.

  • Both Vercel previews (Deploy Remote Flows Preview, Deploy Cost Calculator Preview) build on this PR.

  • E2E (example/, all browsers): 21 passed, 6 failed. The 6 failures are onboard-basic-employee and onboard-germany-employee ("Preview Employment Agreement" instead of "Review"). They fail the same way on a main build with the local test company.

  • Tested against the example/ app in a browser

  • Feature flag: N/A

🤖 Generated with Claude Code


Note

Medium Risk
Wide CI/release and install-path changes with no runtime code edits; misconfiguration could break builds or Vercel git-dependency installs until validated on main.

Overview
Migrates the SDK repo root from npm to pnpm (packageManager, pnpm-lock.yaml, root scripts and lockfile path filters). example/ remains on npm for installs in CI and locally; only the root uses pnpm install --frozen-lockfile and pnpm run in workflows (with Corepack enabled and pnpm caching on setup-node).

CI and release automation are updated across pr, ci-main, coverage, size-check, release, etc., including fallback npm ci on base branches that still lack pnpm-lock.yaml. pnpm-workspace.yaml only configures allowBuilds (no workspace packages). Renovate adds pnpmDedupe.

Vercel / example deploy fixes: example/vercel.json pins npm@11.6.2 for installing the git-pinned SDK root; example/vite.config.mts sets an empty inline PostCSS config so the example build does not pick up the root Tailwind PostCSS setup. Root /package-lock.json is gitignored; prepare stays npm run build for npm/git-dependency consumers.

Helper scripts (release, worktree, seed-onboarding) and docs comments switch to pnpm at the root where applicable.

Reviewed by Cursor Bugbot for commit ce90bf9. Bugbot is set up for automated code reviews on this repo. Configure here.

@github-actions

github-actions Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Already up to date
Done in 422ms using pnpm v11.10.0

📦 Bundle Size Report

Metric Current Previous Change Status
Total (gzip) 228.77 kB 228.77 kB 0 B (0%) 🟢
Total (raw) 637.47 kB 637.47 kB 0 B (0%) 🟢
CSS (gzip) 21.94 kB 21.94 kB 0 B (0%) 🟢
CSS (raw) 114.43 kB 114.43 kB 0 B (0%) 🟢

Size Limits

  • ✅ Total gzipped: 228.77 kB / 350 kB (65.4%)
  • ✅ Total raw: 637.47 kB / 850 kB (75.0%)
  • ✅ CSS gzipped: 21.94 kB / 25 kB (87.8%)

Largest Files (Top 5)

  1. index.esm-wIkXrqU6.js - 11.4 kB (0 B (0%))
  2. styles.css - 10.97 kB (0 B (0%))
  3. index.css - 10.97 kB (0 B (0%))
  4. internals-Bfee4wlS.js - 6.12 kB (0 B (0%))
  5. hooks-CB6-_h3s.js - 5.84 kB (0 B (0%))
View All Files (291 total)
File Size (gzip) Change
index.esm-wIkXrqU6.js 11.4 kB 0 B (0%)
styles.css 10.97 kB 0 B (0%)
index.css 10.97 kB 0 B (0%)
internals-Bfee4wlS.js 6.12 kB 0 B (0%)
hooks-CB6-_h3s.js 5.84 kB 0 B (0%)
sdk.gen-FtLNfTcH.js 5.54 kB 0 B (0%)
index.js 5.51 kB 0 B (0%)
flows/Onboarding/hooks.js 4.52 kB 0 B (0%)
utils-CUgvJHl4.js 4.07 kB 0 B (0%)
FieldSetField-CDERaaih.js 4.03 kB 0 B (0%)

✅ Bundle size check passed

@github-actions

github-actions Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Already up to date
Done in 413ms using pnpm v11.10.0

📊 Coverage Report

⚪ Coverage unchanged

Metric Current Previous Change Status
Lines 89.31% 89.31% 0% ⚪
Statements 88.86% 88.86% 0% ⚪
Functions 88.07% 88.07% 0% ⚪
Branches 80.36% 80.36% 0% ⚪

Detailed Breakdown

Lines Coverage
  • Covered: 5249 / 5877
  • Coverage: 89.31%
  • Change: 0% (0 lines)
Statements Coverage
  • Covered: 5347 / 6017
  • Coverage: 88.86%
  • Change: 0% (0 statements)
Functions Coverage
  • Covered: 1402 / 1592
  • Coverage: 88.07%
  • Change: 0% (0 functions)
Branches Coverage
  • Covered: 3249 / 4043
  • Coverage: 80.36%
  • Change: 0% (0 branches)

✅ Coverage check passed

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

if: steps.check_script.outputs.exists == 'true'
working-directory: base
run: npm run size -- --output ../out/base-bundle.json
run: pnpm run size --output ../out/base-bundle.json

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Base size job uses parent workspace

Medium Severity

The base checkout lives in base/ under this PR's pnpm-workspace.yaml, but the workflow still runs pnpm run build and pnpm run size there after a possible npm ci. pnpm walks up to the parent workspace, so those steps can build or measure the current branch instead of the base ref.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 3944715. Configure here.

Jordi Vidaller and others added 6 commits October 8, 2026 15:32
Pin pnpm 11.10.0 through packageManager, switch the root scripts to
pnpm and replace package-lock.json with pnpm-lock.yaml (imported from
the npm lockfile, so resolved versions are unchanged).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Enable Corepack before setup-node and install the root with
pnpm install --frozen-lockfile. example/ keeps installing with npm.
Base-branch jobs fall back to npm ci while the base still has a
package-lock.json.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The root is installed with pnpm now; an accidental npm install at the
root would otherwise recreate an untracked package-lock.json that is easy
to commit by mistake. example/ still uses npm, so only the root file is
ignored.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…-4975)

Vercel installs example/ with npm and pulls the SDK as a git dependency,
so npm clones the root, installs its dependencies and runs prepare.

- Without package-lock.json that nested install resolves from scratch,
  which crashes npm before 11.6 ("Cannot read properties of null
  (reading 'edgesOut')"). Vercel's Node 22 ships npm 10, so the install
  command now runs a pinned npm 11.6.2.
- prepare goes back to npm run build so it works where pnpm is not
  installed (npm git-dependency preparation); pnpm install still runs it.
- example/ sets an inline PostCSS config so Vite stops picking up the
  root postcss.config.mjs, whose Tailwind plugin is not installed in the
  example deploy. The example build output is unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@jordividaller
jordividaller force-pushed the chore/pbyr-4975-move-sdk-root-to-pnpm branch from 3944715 to 3fa0f89 Compare October 8, 2026 13:42
@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Deploy preview for remote-flows ready!

Project:remote-flows
Status: ✅  Deploy successful!
Preview URL:https://remote-flows-dvrii96h9-remotecom.vercel.app
Latest Commit:3fa0f89

Deployed with vercel-action

@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Deploy preview for adp-cost-calculator ready!

Project:adp-cost-calculator
Status: ✅  Deploy successful!
Preview URL:https://adp-cost-calculator-dneczr3uq-remotecom.vercel.app
Latest Commit:3fa0f89

Deployed with vercel-action

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

There are 2 total unresolved issues (including 1 from previous review).

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 3fa0f89. Configure here.

if: steps.check_script.outputs.exists == 'true'
working-directory: base
run: npm run size -- --output ../out/base-bundle.json
run: pnpm run size --output ../out/base-bundle.json

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Base jobs ignore npm fallback

Medium Severity

The base-branch install step switches to npm ci when pnpm-lock.yaml is missing, but the following build, size, coverage, and extract steps always run pnpm run. This PR’s base is still on npm, so those commands run against an npm-installed tree. In size-check.yml they also run inside base/ under the PR’s pnpm-workspace.yaml, so pnpm can pick up the parent workspace instead of the base package. Bundle-size and coverage comparison against main can fail or compare the wrong tree until the fallback is removed.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 3fa0f89. Configure here.

@jordividaller jordividaller self-assigned this Oct 8, 2026
@jordividaller
jordividaller force-pushed the chore/pbyr-4975-move-sdk-root-to-pnpm branch 2 times, most recently from ce90bf9 to 3fa0f89 Compare October 8, 2026 14:39

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant