Skip to content

chore: harden pnpm installs - #289

Merged
brightiron merged 5 commits into
developfrom
chore/pnpm-hardening
May 14, 2026
Merged

brightiron merged 5 commits into
developfrom
chore/pnpm-hardening

Conversation

@0xJem

@0xJem 0xJem commented May 12, 2026

Copy link
Copy Markdown
Member

Summary

  • adds pnpm workspace hardening settings
  • allows pnpm versions >=10.33.0 via engines.pnpm
  • removes the exact packageManager pin so pnpm 11 is not forced back to 10.33.0

Validation

  • parsed package.json as JSON
  • confirmed pnpm reads minimumReleaseAge from pnpm-workspace.yaml

@coderabbitai

coderabbitai Bot commented May 12, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Rate limit exceeded

@0xJem has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 8 minutes and 52 seconds before requesting another review.

You’ve run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 8e9b03bd-405c-44fa-bfc7-43bb09ceac2b

📥 Commits

Reviewing files that changed from the base of the PR and between 31168ca and 8ab42ed.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (3)
  • .npmrc
  • package.json
  • pnpm-workspace.yaml
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/pnpm-hardening

Comment @coderabbitai help to get the list of available commands and usage tips.

@0xJem 0xJem self-assigned this May 13, 2026
@0xJem
0xJem marked this pull request as ready for review May 13, 2026 16:02
@brightiron
brightiron merged commit 0bb6a52 into develop May 14, 2026
15 checks passed
Yurii3721 added a commit that referenced this pull request May 20, 2026
* script: add script to change the kernel executor for a given chain

* chore: record kernel executor on Arbitrum

* chore(env): record kernel executor config

* script: codex scripts

* script: pin foundry to v1.5.1

* chore(gitignore): ignore pnpm store

* feat(batch): add Treasury Working Group setup

Cross-port of the multisig setup/env entry from feat/susde-aave-loop commit f75cf2f, renamed from yield multisig to Treasury Working Group.

* feat(batch): add heartbeat validation skip

Cross-port of configurable heartbeat validation skip from feat/susde-aave-loop commit f385238. Also includes Safe tx detail logging from commit ef972d0, which was part of the requested batch-script port.

* fix(scripts): update kernel executor pragma

* fix(proposals): update OIP 194A test pragma

* Script to update Cooler OLTV on Sepolia

* fix: adjust compiler version

* Add missing script for transferring token pool ownership

* chore(coderabbit): relax script review guidance

* chore(lint): exclude irrelevant forge lint rules

* ci(lint): add forge lint inline annotations

* ci: add missing permission

* chore(deps): pin fast-uri to 3.1.2

* docs(workflow): streamline repo publish process

* chore: harden pnpm installs (#289)

* chore: harden pnpm installs

* chore: pin pnpm version in workflows

* chore: harden pnpm configuration

* chore: move pnpm config to workspace

* chore: format pnpm workspace config

* feat(policies): add TimelockBatchQueue with atomic batched timelocked actions

* refactor(roles): move LZ bridge role constants in RoleDefinitions

* feat(lz-bridge): implement LZBridgeAndDelegateConfig timelock policy

Introduce a timelock policy that owns LayerZero bridge configuration on
behalf of the LZBridgeGateway, LZEndpointDelegate, and periphery
LZCrossChainBridge. The policy holds the bridge_configurator role on
the gateway/delegate and is pinned as configurator on the periphery
bridge; every privileged mutator now flows through its typed
queue/execute helpers, with batched atomic actions via queueBatch and
emergency-only cancellation. Updates the OCG proposal, deploy script,
ops batches, tests, documentation, audit scope.

* refactor(lz-bridge-conf): share _setTarget* helpers and tighten revert assertions

* refactor(lz-bridge): collapse per-target queue helpers into single queue batch

* refactor(lz-bridge): gate delegate skip/nilify/burn/clear directly, not via bridge_configurator

* feat(lz-bridge-conf): validate payload lengths to reject trailing-bytes encodings

* fix(timelock-batch-queue,lz-bridge-config): flip queue event order; replace child with derived, drop return-param trailing underscores

* refactor(lz-bridge-conf): drop trailing underscores from return params

* docs(lz-bridge): simplify

* docs(lz-bridge): note bridge_configurator timelock-bypass caveat

* chore(deps): patch brace-expansion vulnerability

* chore(pnpm): remove npx preinstall guard

* test(lz-bridge-conf): cover admin-only revert path in mixed-role queue batch

* docs(timelock-queue): add bool type to supportsInterface return NatSpec

* test(lz-bridge-conf): add per-function batch-role rejection coverage for queue()

* feat(lz-bridge-conf,timelock-batch): bind queued sub-actions to queue-time target kind

* docs(lz-bridge): correct stale wording in audit README feature list

* fix(timelock-batch-queue): bump nextActionId before sub-action hooks

* docs(lz-bridge): align MIGRATION with current rollout state

---------

Co-authored-by: Jem <0x0xjem@gmail.com>
Co-authored-by: Jem <91760036+0xJem@users.noreply.github.com>
@0xJem
0xJem deleted the chore/pnpm-hardening branch May 20, 2026 12:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants