Repository navigation
fix(ci): add missing packages field to pnpm-workspace.yaml - #1760
Merged
Merged
Conversation
pnpm-workspace.yaml only declared allowBuilds, no packages: list. pnpm 9 requires packages: even for a non-recursive `pnpm run <script>` at the workspace root — reproduced locally via `npx pnpm@9 run build`, which failed with 'packages field missing or empty' until this was added, matching release PR #1754's compressed-size CI failure. #1759 removed the workflow's pnpm setup step as a workaround, but compressed-size-action picks pnpm anyway once it sees the root pnpm-lock.yaml, regardless of that step — it just started failing on 'Unable to locate executable file: pnpm' instead. Restoring the setup step now that the real cause (missing packages: field) is fixed.
LucasSantana-Dev
enabled auto-merge (squash)
July 10, 2026 13:47
📝 WalkthroughWalkthroughThe pnpm workspace configuration now defines package globs and dependency policies. The bundle-size workflow explicitly installs pnpm v9 before running compressed-size analysis. Changespnpm workspace and bundle workflow
Estimated code review effort: 2 (Simple) | ~10 minutes 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
|
Failed to generate code suggestions for PR |
There was a problem hiding this comment.
No issues found across 2 files
Requires human review: Changes CI workflow (bundle-size.yml) and pnpm config. CI/workflow configuration changes have broader impact and should be reviewed by a human.
Re-trigger cubic
Addresses 3 Semgrep/CodeQL findings surfaced on this file once it was touched: blockExoticSubdeps, minimumReleaseAge, trustPolicy are all pnpm >=10.16 settings. CI pins pnpm 9 (pnpm/action-setup), which silently ignores them (verified: npx pnpm@9 run build still succeeds) — they take effect for contributors on newer local pnpm per CONTRIBUTING.md's documented pnpm install workflow.
|
Merged
LucasSantana-Dev
added a commit
that referenced
this pull request
Jul 10, 2026
🤖 I have created a release *beep* *boop* --- <details><summary>2.34.0</summary> ## [2.34.0](v2.33.1...v2.34.0) (2026-07-10) ### Features * **twitch:** use Promise.allSettled for per-event subscription error logging ([#1749](#1749)) ([6691305](6691305)) ### Bug Fixes * [#1699](#1699) ([eef5aee](eef5aee)) * **backend:** migrate webhooks to use canonical timingsafekey comparison ([#1747](#1747)) ([eef5aee](eef5aee)) * **backend:** wrap lastfm routes with asynchandler ([#1726](#1726)) ([ce51d86](ce51d86)) * **batch-move:** graceful attachment-fetch degradation + mid-loop client re-check ([#1750](#1750)) ([f21a0ce](f21a0ce)) * **bot:** approve @discordjs/opus install script — P0 music playback outage ([#1757](#1757)) ([9d894e4](9d894e4)) * **ci:** add missing packages field to pnpm-workspace.yaml ([#1760](#1760)) ([a4c585d](a4c585d)) * **ci:** remove pnpm shim from bundle-size workflow ([#1759](#1759)) ([eaf676f](eaf676f)) * **deploy:** increase validation timeout to 10min ([#1743](#1743)) ([07891ec](07891ec)) * **docker:** copy+chown [@prisma](https://github.com/prisma) engines in production-backend — P0 deploy pipeline blocker ([#1758](#1758)) ([a70d0e8](a70d0e8)) * eliminate mock state pollution in bot tests and remove resetMocks config ([#1741](#1741)) ([2e5fd94](2e5fd94)) * **frontend:** prevent state updates after unmount ([#1748](#1748)) ([f4e7c45](f4e7c45)) * pin file-type to resolve CI flake [#1740](#1740) ([#1753](#1753)) ([6b8e527](6b8e527)) * reduce Jest maxWorkers and add DB pool config for test stability ([#1751](#1751)) ([cfead33](cfead33)) * use fake timers in ReminderService.spec to prevent race condition ([#1745](#1745)) ([ba2908c](ba2908c)) </details> --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please).
Merged
3 tasks done
Merged
Merged
This was referenced Oct 1, 2026
Merged
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Summary
Test plan
Summary by cubic
Fixes the
compressed-sizeCI job by adding the missingpackagesfield inpnpm-workspace.yamland restoring thepnpmsetup in the bundle-size workflow. Also adds supply-chain guardrails to the workspace config without affecting CI.Bug Fixes
packages: ['packages/*']topnpm-workspace.yaml(required bypnpm@9even for rootpnpm run).pnpmsetup sopreactjs/compressed-size-actioncan run (it auto-pickspnpmdue to the rootpnpm-lock.yaml).Refactors
pnpm-workspace.yamlwithblockExoticSubdeps,minimumReleaseAge, andtrustPolicy: no-downgrade; ignored by CI’spnpm@9, effective on newer localpnpm.Written for commit 88f8692. Summary will update on new commits.
Summary by CodeRabbit