Skip to content

chore: remove dead pnpm lockfile, fix contributing-guide drift - #1967

Merged
LucasSantana-Dev merged 4 commits into
mainfrom
chore/remove-dead-pnpm-lockfile
Aug 12, 2026
Merged

LucasSantana-Dev merged 4 commits into
mainfrom
chore/remove-dead-pnpm-lockfile

Conversation

@LucasSantana-Dev

@LucasSantana-Dev LucasSantana-Dev commented Aug 10, 2026 •

Copy link
Copy Markdown
Owner

Summary

Closes #1538 (open 7 weeks, labeled ready-for-human — surfacing that label explicitly since this deletes a file CONTRIBUTING.md currently says never to delete).

  • pnpm-lock.yaml/pnpm-workspace.yaml last touched 2026-07-02 (5+ weeks stale) while package-lock.json updates constantly and CI exclusively runs npm ci — dead tooling from an abandoned experiment.
  • CONTRIBUTING.md told contributors to pnpm install and explicitly said "never delete pnpm-lock.yaml." Any external contributor following it verbatim gets a 5-week-stale dependency tree that diverges from what CI actually tests against — the exact kind of onboarding trap the "clear the house" pass this session was meant to catch.
  • Replaced every pnpm command with the npm equivalent, using the existing root package.json script aliases (test:bot, test:backend, dev:frontend, test:e2e) rather than raw --workspace= flags, matching this repo's own established DX.

Recommendation, not unilateral judgment call: the evidence (CI, README, staleness) overwhelmingly favors npm as the actual standard here — this isn't a coin-flip. But since #1538 was explicitly marked ready-for-human, flagging that clearly rather than silently overriding it. Happy to hold this PR if you'd rather make the call yourself.

Verified

  • npm run test:bot -- --testPathPatterns='clear\.spec\.ts' — confirmed the nested npm run args actually forward correctly (the exact command now documented in CONTRIBUTING.md)
  • tsc --noEmit clean (ran as part of pre-commit)
  • Checked for other pnpm references repo-wide: .gitignore's defensive per-package exclusion and .dockerignore's generic debug-log pattern are harmless no-ops, left alone; docs/roadmap.md's reference to chore: repo carries two lockfiles (package-lock.json + pnpm-lock.yaml) that drift independently #1538 will read as resolved once that issue closes.

Summary by cubic

Removed stale pnpm files and updated CONTRIBUTING.md to use npm so local setup matches CI. Prevents divergent installs and closes #1538.

  • Refactors
    • Deleted unused pnpm-lock.yaml and pnpm-workspace.yaml (CI runs npm ci with package-lock.json).
    • Replaced pnpm commands with npm scripts (test:bot, test:backend, dev:frontend, test:e2e) and updated the hard rule to reference package-lock.json.

Written for commit 2b39ab7. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Documentation

    • Updated contribution instructions to use npm-based commands.
    • Added guidance for running targeted bot tests.
    • Updated lockfile guidance to reference package-lock.json.
  • Chores

    • Removed workspace-specific package manager configuration.

pnpm-lock.yaml/pnpm-workspace.yaml haven't been touched since 2026-07-02
(5+ weeks) while package-lock.json updates constantly. CI exclusively
runs npm ci (.github/workflows/ci.yml), README says npm install, and
package.json declares npm workspaces with no packageManager field. The
pnpm lockfile was stale, unused tooling.

Worse: CONTRIBUTING.md told contributors to `pnpm install` and
explicitly said "never delete pnpm-lock.yaml" — a new contributor
following it verbatim would get a 5-week-stale dependency tree that
diverges from what CI actually tests against. Updated every command to
the npm equivalent (using the existing root package.json script
aliases: test:bot, test:backend, dev:frontend, test:e2e) and fixed the
hard-rule line to reference package-lock.json instead.

Verified each replacement command actually works (npm run test:bot --
--testPathPatterns=... correctly forwards through the nested npm run).

Closes #1538
@coderabbitai

coderabbitai Bot commented Aug 10, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: f9bcaf9a-4fc2-4ba8-90b7-2800f264da4e

📥 Commits

Reviewing files that changed from the base of the PR and between 23eaba2 and cacc7ad.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (2)
  • CONTRIBUTING.md
  • pnpm-workspace.yaml
💤 Files with no reviewable changes (1)
  • pnpm-workspace.yaml

📝 Walkthrough

Walkthrough

The contribution guide now uses npm installation and scripts. Its lockfile rule now protects package-lock.json. The pnpm-workspace.yaml configuration was removed.

Changes

npm workflow cleanup

Layer / File(s) Summary
Contribution workflow and workspace configuration
CONTRIBUTING.md, pnpm-workspace.yaml
Getting-started instructions now use npm commands. The lockfile rule now prohibits deleting package-lock.json. The pnpm workspace configuration was removed.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 inconclusive)

Check name Status Explanation Resolution
Linked Issues check ❓ Inconclusive The documentation and workspace changes support npm authority, but deletion of pnpm-lock.yaml cannot be verified because the file was excluded by path filters. Provide reviewable evidence that pnpm-lock.yaml was deleted, or remove the exclusion so the lockfile change can be verified.
✅ Passed checks (4 passed)
Check name Status Explanation
Out of Scope Changes check ✅ Passed The changes remain within the stated objective of removing obsolete pnpm configuration and aligning contributor instructions with npm-based workflows.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main changes: removing obsolete pnpm configuration and updating the contributing guide.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/remove-dead-pnpm-lockfile

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown

Failed to generate code suggestions for PR

@github-actions

github-actions Bot commented Aug 10, 2026 •

Copy link
Copy Markdown
Warnings
⚠️

Big PR — 9735 lines changed across 1 files. Consider splitting into smaller, reviewable chunks.

Generated by 🚫 dangerJS against 2b39ab7

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 3 files

Requires human review: The diff only removes pnpm files and edits CONTRIBUTING; the decisive claim that CI exclusively uses npm and pnpm is dead is not visible in the diff. Human should verify tooling before deleting the lockfile and changing the hard rule.
Tip: cubic can generate docs of your entire codebase and keep them up to date. Try it here.

Re-trigger cubic

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Worth a look — the grounded gate found no coupling regressions or blocking issues, but 2 advisory finding(s) below merit a look before merge.


Graphify review — findings

This pull request migrates the project's package manager from pnpm to npm. In CONTRIBUTING.md, it updates the setup and per-package test/dev commands (e.g., pnpm --filter ... → npm run ...) and changes a hard rule to reference package-lock.json instead of pnpm-lock.yaml. It also deletes the pnpm-lock.yaml lockfile.

Worth a look

  • Package manager migration removes the only committed lockfile — pnpm-lock.yaml:1 · Escalate · high
    • agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
  • Dependency lockfile removed — pnpm-lock.yaml:1 · Escalate · medium
    • agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 11 functions depend on the 11 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 11 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 11 function(s) in the blast radius were not formally verified this run

@LucasSantana-Dev
LucasSantana-Dev enabled auto-merge (squash) August 11, 2026 23:21

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Worth a look — the grounded gate found no coupling regressions or blocking issues, but 2 advisory finding(s) below merit a look before merge.


Graphify review — findings

This pull request migrates the project's package manager from pnpm to npm. In CONTRIBUTING.md, it updates all install/test/dev commands (e.g. pnpm install → npm install, pnpm --filter invocations → npm run scripts) and changes lockfile references from pnpm-lock.yaml to package-lock.json. It also deletes the pnpm-lock.yaml file.

Worth a look

  • Repository lockfile removed without replacement — pnpm-lock.yaml:1 · Escalate · high
    • agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
  • Deleted dependency lockfile removes integrity-pinned installs — pnpm-lock.yaml:1 · Escalate · medium
    • agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 11 functions depend on the 11 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 11 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 11 function(s) in the blast radius were not formally verified this run

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Worth a look — the grounded gate found no coupling regressions or blocking issues, but 1 advisory finding(s) below merit a look before merge.


Graphify review — findings

This pull request migrates the project's package manager tooling from pnpm to npm. In CONTRIBUTING.md, it updates the setup, test, and dev command examples (e.g., pnpm install → npm install, pnpm --filter commands → npm run scripts) and changes the hard rule referencing the lockfile from pnpm-lock.yaml to package-lock.json. It also deletes the pnpm-lock.yaml file.

Worth a look

  • Package manager migration deletes the only lockfile — pnpm-lock.yaml:1 · Escalate · high
    • agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 11 functions depend on the 11 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 11 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 11 function(s) in the blast radius were not formally verified this run

@sonarqubecloud

Copy link
Copy Markdown

@LucasSantana-Dev
LucasSantana-Dev merged commit e249fc0 into main Aug 12, 2026
36 checks passed
@LucasSantana-Dev
LucasSantana-Dev deleted the chore/remove-dead-pnpm-lockfile branch August 12, 2026 00:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

chore: repo carries two lockfiles (package-lock.json + pnpm-lock.yaml) that drift independently

1 participant