chore: harden pnpm installs - #289
Conversation
|
Warning Rate limit exceeded
You’ve run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (3)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
* script: add script to change the kernel executor for a given chain * chore: record kernel executor on Arbitrum * chore(env): record kernel executor config * script: codex scripts * script: pin foundry to v1.5.1 * chore(gitignore): ignore pnpm store * feat(batch): add Treasury Working Group setup Cross-port of the multisig setup/env entry from feat/susde-aave-loop commit f75cf2f, renamed from yield multisig to Treasury Working Group. * feat(batch): add heartbeat validation skip Cross-port of configurable heartbeat validation skip from feat/susde-aave-loop commit f385238. Also includes Safe tx detail logging from commit ef972d0, which was part of the requested batch-script port. * fix(scripts): update kernel executor pragma * fix(proposals): update OIP 194A test pragma * Script to update Cooler OLTV on Sepolia * fix: adjust compiler version * Add missing script for transferring token pool ownership * chore(coderabbit): relax script review guidance * chore(lint): exclude irrelevant forge lint rules * ci(lint): add forge lint inline annotations * ci: add missing permission * chore(deps): pin fast-uri to 3.1.2 * docs(workflow): streamline repo publish process * chore: harden pnpm installs (#289) * chore: harden pnpm installs * chore: pin pnpm version in workflows * chore: harden pnpm configuration * chore: move pnpm config to workspace * chore: format pnpm workspace config * feat(policies): add TimelockBatchQueue with atomic batched timelocked actions * refactor(roles): move LZ bridge role constants in RoleDefinitions * feat(lz-bridge): implement LZBridgeAndDelegateConfig timelock policy Introduce a timelock policy that owns LayerZero bridge configuration on behalf of the LZBridgeGateway, LZEndpointDelegate, and periphery LZCrossChainBridge. The policy holds the bridge_configurator role on the gateway/delegate and is pinned as configurator on the periphery bridge; every privileged mutator now flows through its typed queue/execute helpers, with batched atomic actions via queueBatch and emergency-only cancellation. Updates the OCG proposal, deploy script, ops batches, tests, documentation, audit scope. * refactor(lz-bridge-conf): share _setTarget* helpers and tighten revert assertions * refactor(lz-bridge): collapse per-target queue helpers into single queue batch * refactor(lz-bridge): gate delegate skip/nilify/burn/clear directly, not via bridge_configurator * feat(lz-bridge-conf): validate payload lengths to reject trailing-bytes encodings * fix(timelock-batch-queue,lz-bridge-config): flip queue event order; replace child with derived, drop return-param trailing underscores * refactor(lz-bridge-conf): drop trailing underscores from return params * docs(lz-bridge): simplify * docs(lz-bridge): note bridge_configurator timelock-bypass caveat * chore(deps): patch brace-expansion vulnerability * chore(pnpm): remove npx preinstall guard * test(lz-bridge-conf): cover admin-only revert path in mixed-role queue batch * docs(timelock-queue): add bool type to supportsInterface return NatSpec * test(lz-bridge-conf): add per-function batch-role rejection coverage for queue() * feat(lz-bridge-conf,timelock-batch): bind queued sub-actions to queue-time target kind * docs(lz-bridge): correct stale wording in audit README feature list * fix(timelock-batch-queue): bump nextActionId before sub-action hooks * docs(lz-bridge): align MIGRATION with current rollout state --------- Co-authored-by: Jem <0x0xjem@gmail.com> Co-authored-by: Jem <91760036+0xJem@users.noreply.github.com>
Summary
engines.pnpmpackageManagerpin so pnpm 11 is not forced back to 10.33.0Validation
package.jsonas JSONminimumReleaseAgefrompnpm-workspace.yaml