Repository navigation
chore: remove dead pnpm lockfile, fix contributing-guide drift - #1967
Conversation
pnpm-lock.yaml/pnpm-workspace.yaml haven't been touched since 2026-07-02 (5+ weeks) while package-lock.json updates constantly. CI exclusively runs npm ci (.github/workflows/ci.yml), README says npm install, and package.json declares npm workspaces with no packageManager field. The pnpm lockfile was stale, unused tooling. Worse: CONTRIBUTING.md told contributors to `pnpm install` and explicitly said "never delete pnpm-lock.yaml" — a new contributor following it verbatim would get a 5-week-stale dependency tree that diverges from what CI actually tests against. Updated every command to the npm equivalent (using the existing root package.json script aliases: test:bot, test:backend, dev:frontend, test:e2e) and fixed the hard-rule line to reference package-lock.json instead. Verified each replacement command actually works (npm run test:bot -- --testPathPatterns=... correctly forwards through the nested npm run). Closes #1538
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (2)
💤 Files with no reviewable changes (1)
📝 WalkthroughWalkthroughThe contribution guide now uses npm installation and scripts. Its lockfile rule now protects Changesnpm workflow cleanup
Estimated code review effort: 1 (Trivial) | ~5 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 inconclusive)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Failed to generate code suggestions for PR |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
There was a problem hiding this comment.
No issues found across 3 files
Requires human review: The diff only removes pnpm files and edits CONTRIBUTING; the decisive claim that CI exclusively uses npm and pnpm is dead is not visible in the diff. Human should verify tooling before deleting the lockfile and changing the hard rule.
Tip: cubic can generate docs of your entire codebase and keep them up to date. Try it here.
Re-trigger cubic
There was a problem hiding this comment.
Graphify reviewed this change.
Worth a look — the grounded gate found no coupling regressions or blocking issues, but 2 advisory finding(s) below merit a look before merge.
Graphify review — findings
This pull request migrates the project's package manager from pnpm to npm. In CONTRIBUTING.md, it updates the setup and per-package test/dev commands (e.g., pnpm --filter ... → npm run ...) and changes a hard rule to reference package-lock.json instead of pnpm-lock.yaml. It also deletes the pnpm-lock.yaml lockfile.
Worth a look
- Package manager migration removes the only committed lockfile —
pnpm-lock.yaml:1· Escalate · high- agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
- Dependency lockfile removed —
pnpm-lock.yaml:1· Escalate · medium- agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 11 functions depend on the 11 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 11 functions in the blast radius were not formally verified this run (proofs are advisory here).
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 11 function(s) in the blast radius were not formally verified this run
There was a problem hiding this comment.
Graphify reviewed this change.
Worth a look — the grounded gate found no coupling regressions or blocking issues, but 2 advisory finding(s) below merit a look before merge.
Graphify review — findings
This pull request migrates the project's package manager from pnpm to npm. In CONTRIBUTING.md, it updates all install/test/dev commands (e.g. pnpm install → npm install, pnpm --filter invocations → npm run scripts) and changes lockfile references from pnpm-lock.yaml to package-lock.json. It also deletes the pnpm-lock.yaml file.
Worth a look
- Repository lockfile removed without replacement —
pnpm-lock.yaml:1· Escalate · high- agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
- Deleted dependency lockfile removes integrity-pinned installs —
pnpm-lock.yaml:1· Escalate · medium- agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 11 functions depend on the 11 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 11 functions in the blast radius were not formally verified this run (proofs are advisory here).
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 11 function(s) in the blast radius were not formally verified this run
There was a problem hiding this comment.
Graphify reviewed this change.
Worth a look — the grounded gate found no coupling regressions or blocking issues, but 1 advisory finding(s) below merit a look before merge.
Graphify review — findings
This pull request migrates the project's package manager tooling from pnpm to npm. In CONTRIBUTING.md, it updates the setup, test, and dev command examples (e.g., pnpm install → npm install, pnpm --filter commands → npm run scripts) and changes the hard rule referencing the lockfile from pnpm-lock.yaml to package-lock.json. It also deletes the pnpm-lock.yaml file.
Worth a look
- Package manager migration deletes the only lockfile —
pnpm-lock.yaml:1· Escalate · high- agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 11 functions depend on the 11 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 11 functions in the blast radius were not formally verified this run (proofs are advisory here).
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 11 function(s) in the blast radius were not formally verified this run
|



Summary
Closes #1538 (open 7 weeks, labeled
ready-for-human— surfacing that label explicitly since this deletes a file CONTRIBUTING.md currently says never to delete).pnpm-lock.yaml/pnpm-workspace.yamllast touched 2026-07-02 (5+ weeks stale) whilepackage-lock.jsonupdates constantly and CI exclusively runsnpm ci— dead tooling from an abandoned experiment.CONTRIBUTING.mdtold contributors topnpm installand explicitly said "never delete pnpm-lock.yaml." Any external contributor following it verbatim gets a 5-week-stale dependency tree that diverges from what CI actually tests against — the exact kind of onboarding trap the "clear the house" pass this session was meant to catch.package.jsonscript aliases (test:bot,test:backend,dev:frontend,test:e2e) rather than raw--workspace=flags, matching this repo's own established DX.Recommendation, not unilateral judgment call: the evidence (CI, README, staleness) overwhelmingly favors npm as the actual standard here — this isn't a coin-flip. But since #1538 was explicitly marked
ready-for-human, flagging that clearly rather than silently overriding it. Happy to hold this PR if you'd rather make the call yourself.Verified
npm run test:bot -- --testPathPatterns='clear\.spec\.ts'— confirmed the nestednpm runargs actually forward correctly (the exact command now documented in CONTRIBUTING.md)tsc --noEmitclean (ran as part of pre-commit).gitignore's defensive per-package exclusion and.dockerignore's generic debug-log pattern are harmless no-ops, left alone;docs/roadmap.md's reference to chore: repo carries two lockfiles (package-lock.json + pnpm-lock.yaml) that drift independently #1538 will read as resolved once that issue closes.Summary by cubic
Removed stale
pnpmfiles and updatedCONTRIBUTING.mdto usenpmso local setup matches CI. Prevents divergent installs and closes #1538.pnpm-lock.yamlandpnpm-workspace.yaml(CI runsnpm ciwithpackage-lock.json).pnpmcommands withnpmscripts (test:bot,test:backend,dev:frontend,test:e2e) and updated the hard rule to referencepackage-lock.json.Written for commit 2b39ab7. Summary will update on new commits.
Summary by CodeRabbit
Documentation
package-lock.json.Chores