Skip to content

fix(ci): add missing packages field to pnpm-workspace.yaml - #1760

Merged
LucasSantana-Dev merged 2 commits into
mainfrom
fix/pnpm-workspace-packages-field
Jul 10, 2026
Merged

LucasSantana-Dev merged 2 commits into
mainfrom
fix/pnpm-workspace-packages-field

Conversation

@LucasSantana-Dev

@LucasSantana-Dev LucasSantana-Dev commented Jul 10, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Root cause of release PR chore: release 2.34.0 #1754's persistent `compressed-size` failure ("packages field missing or empty"): `pnpm-workspace.yaml` only declared `allowBuilds`, never a `packages:` list. pnpm 9 requires `packages:` even for a non-recursive `pnpm run <script>` at the workspace root.
  • Reproduced locally with `npx pnpm@9 run build` — failed identically until `packages: ['packages/*']` was added.
  • fix(ci): remove pnpm shim from bundle-size workflow #1759 (merged) removed the workflow's pnpm setup step as a workaround, on the theory pnpm itself was the problem — but `compressed-size-action` picks pnpm regardless once it sees the root `pnpm-lock.yaml` (used for the documented alt `pnpm install` dev workflow in CONTRIBUTING.md), so removing the setup step just changed the failure to "Unable to locate executable file: pnpm". Restoring that step now that the actual cause is fixed.

Test plan

  • Reproduced the original failure and the fix locally with pnpm 9 (`npx pnpm@9 run build`)
  • CI green on this PR
  • chore: release 2.34.0 #1754 picks this up via update-branch and its compressed-size check passes

Summary by cubic

Fixes the compressed-size CI job by adding the missing packages field in pnpm-workspace.yaml and restoring the pnpm setup in the bundle-size workflow. Also adds supply-chain guardrails to the workspace config without affecting CI.

  • Bug Fixes

    • Added packages: ['packages/*'] to pnpm-workspace.yaml (required by pnpm@9 even for root pnpm run).
    • Restored pnpm setup so preactjs/compressed-size-action can run (it auto-picks pnpm due to the root pnpm-lock.yaml).
  • Refactors

    • Hardened pnpm-workspace.yaml with blockExoticSubdeps, minimumReleaseAge, and trustPolicy: no-downgrade; ignored by CI’s pnpm@9, effective on newer local pnpm.

Written for commit 88f8692. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Chores
    • Improved automated bundle-size checks by standardizing their package manager setup.
    • Expanded workspace configuration to improve dependency consistency and package management safeguards.

pnpm-workspace.yaml only declared allowBuilds, no packages: list. pnpm
9 requires packages: even for a non-recursive `pnpm run <script>` at
the workspace root — reproduced locally via `npx pnpm@9 run build`,
which failed with 'packages field missing or empty' until this was
added, matching release PR #1754's compressed-size CI failure.

#1759 removed the workflow's pnpm setup step as a workaround, but
compressed-size-action picks pnpm anyway once it sees the root
pnpm-lock.yaml, regardless of that step — it just started failing on
'Unable to locate executable file: pnpm' instead. Restoring the setup
step now that the real cause (missing packages: field) is fixed.
@LucasSantana-Dev
LucasSantana-Dev enabled auto-merge (squash) July 10, 2026 13:47
@coderabbitai

coderabbitai Bot commented Jul 10, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

The pnpm workspace configuration now defines package globs and dependency policies. The bundle-size workflow explicitly installs pnpm v9 before running compressed-size analysis.

Changes

pnpm workspace and bundle workflow

Layer / File(s) Summary
Expand pnpm workspace configuration
pnpm-workspace.yaml
Adds the packages/* workspace glob, dependency and trust policies, and preserves the existing build allowlist.
Prepare pnpm for bundle analysis
.github/workflows/bundle-size.yml
Adds a pnpm v9 setup step before the existing compressed-size action.

Estimated code review effort: 2 (Simple) | ~10 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title is concise and accurately reflects the main pnpm workspace fix in this PR.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/pnpm-workspace-packages-field

Comment @coderabbitai help to get the list of available commands.

Comment thread pnpm-workspace.yaml Fixed
Comment thread pnpm-workspace.yaml Fixed
Comment thread pnpm-workspace.yaml Fixed
@github-actions

Copy link
Copy Markdown

Failed to generate code suggestions for PR

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 2 files

Requires human review: Changes CI workflow (bundle-size.yml) and pnpm config. CI/workflow configuration changes have broader impact and should be reviewed by a human.

Re-trigger cubic

Addresses 3 Semgrep/CodeQL findings surfaced on this file once it was
touched: blockExoticSubdeps, minimumReleaseAge, trustPolicy are all
pnpm >=10.16 settings. CI pins pnpm 9 (pnpm/action-setup), which
silently ignores them (verified: npx pnpm@9 run build still succeeds)
— they take effect for contributors on newer local pnpm per
CONTRIBUTING.md's documented pnpm install workflow.
@sonarqubecloud

Copy link
Copy Markdown

@LucasSantana-Dev
LucasSantana-Dev merged commit a4c585d into main Jul 10, 2026
39 checks passed
@LucasSantana-Dev
LucasSantana-Dev deleted the fix/pnpm-workspace-packages-field branch July 10, 2026 14:16
LucasSantana-Dev added a commit that referenced this pull request Jul 10, 2026
🤖 I have created a release *beep* *boop*
---


<details><summary>2.34.0</summary>

##
[2.34.0](v2.33.1...v2.34.0)
(2026-07-10)


### Features

* **twitch:** use Promise.allSettled for per-event subscription error
logging ([#1749](#1749))
([6691305](6691305))


### Bug Fixes

* [#1699](#1699)
([eef5aee](eef5aee))
* **backend:** migrate webhooks to use canonical timingsafekey
comparison
([#1747](#1747))
([eef5aee](eef5aee))
* **backend:** wrap lastfm routes with asynchandler
([#1726](#1726))
([ce51d86](ce51d86))
* **batch-move:** graceful attachment-fetch degradation + mid-loop
client re-check
([#1750](#1750))
([f21a0ce](f21a0ce))
* **bot:** approve @discordjs/opus install script — P0 music playback
outage ([#1757](#1757))
([9d894e4](9d894e4))
* **ci:** add missing packages field to pnpm-workspace.yaml
([#1760](#1760))
([a4c585d](a4c585d))
* **ci:** remove pnpm shim from bundle-size workflow
([#1759](#1759))
([eaf676f](eaf676f))
* **deploy:** increase validation timeout to 10min
([#1743](#1743))
([07891ec](07891ec))
* **docker:** copy+chown [@prisma](https://github.com/prisma) engines in
production-backend — P0 deploy pipeline blocker
([#1758](#1758))
([a70d0e8](a70d0e8))
* eliminate mock state pollution in bot tests and remove resetMocks
config ([#1741](#1741))
([2e5fd94](2e5fd94))
* **frontend:** prevent state updates after unmount
([#1748](#1748))
([f4e7c45](f4e7c45))
* pin file-type to resolve CI flake
[#1740](#1740)
([#1753](#1753))
([6b8e527](6b8e527))
* reduce Jest maxWorkers and add DB pool config for test stability
([#1751](#1751))
([cfead33](cfead33))
* use fake timers in ReminderService.spec to prevent race condition
([#1745](#1745))
([ba2908c](ba2908c))
</details>

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).
This was referenced Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants