Skip to content

fix(deps): keep unused pnpm peers out of production - #11342

Merged
diegosouzapw merged 2 commits into
release/v3.8.50from
fix/v3850-license-policy
Aug 24, 2026
Merged

diegosouzapw merged 2 commits into
release/v3.8.50from
fix/v3850-license-policy

Conversation

@diegosouzapw

@diegosouzapw diegosouzapw commented Aug 24, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Stop pnpm from auto-installing the unused @lobehub/ui peer subtree declared by @lobehub/icons.
  • Keep six unneeded packages with incompatible or unverifiable license metadata out of production installs without adding policy exceptions.
  • Add a regression test that keeps pnpm aligned with the repository's existing npm legacy-peer-deps posture.

The affected subtree was not present in package-lock.json, was not imported by OmniRoute, and existed only because pnpm automatically installed an optional UI peer. With autoInstallPeers: false, a freshly generated temporary pnpm lock contains zero resolutions for @giscus/react, @pierre/diffs, @pierre/theming, @splinetool/runtime, chroma-js, or elkjs.

Related Issues

Validation

Choose the change type and focused loop from the
Contribution Golden Path. The full unit suite,
Vitest, the 60% coverage gate, and the production build all run in CI on this PR (#8329):

  • Change type: build-deploy / dependency policy
  • Focused tests and category gates from the golden path
  • npm run lint — focused ESLint passed; full lint remains delegated to CI
  • Reconciled with the current active release base; focused checks rerun afterward
  • Production-code changes include a new or updated automated test in this PR
  • SonarQube is temporarily opt-in while the private project has no quota; it is not a PR gate.

Exact post-rebase evidence against release/v3.8.50 at 9b14896a6cb61f2eda1c091a219a8558d10e5fb4:

  • node --import tsx/esm --test tests/unit/build/check-licenses.test.ts — 37/37 PASS
  • npm run check:licenses — PASS, 951 production packages, 0 policy violations
  • temporary pnpm lock regeneration — all six unwanted package resolutions absent; lock removed afterward
  • CHANGELOG_BASE_REF=refs/remotes/origin/release/v3.8.50 npm run check:changelog-integrity — PASS
  • Prettier on all three changed paths — PASS
  • git diff --check — PASS

⚠️ The continuous base-red tracker #9985 remains open. Its current report is independently being repaired; inherited release-level results must be compared against this PR's exact merge candidate rather than assigned to this dependency-policy change.

Tests Added Or Updated

  • tests/unit/build/check-licenses.test.ts
    • proves pnpm-workspace.yaml disables peer auto-installation;
    • retains the existing license classifier and allowlist contract tests.

Coverage Notes

  • No src/, open-sse/, electron/, or bin/ production code changed.
  • The behavior is a package-manager policy contract and is exercised directly by the updated Node unit test plus the full production dependency license scan.

Reviewer Notes

  • This deliberately removes the unused dependency subtree instead of adding six license exceptions.
  • No pnpm-lock.yaml is tracked by this PR. A temporary lock was generated only as validation and then deleted.
  • Existing approved exceptions for Sharp's dynamically linked libvips packages, caniuse-lite, and tls-client-node are unchanged.
  • The changelog fragment is named for and links directly to this PR.

@diegosouzapw
diegosouzapw merged commit dafb4ae into release/v3.8.50 Aug 24, 2026
19 of 22 checks passed
@diegosouzapw
diegosouzapw deleted the fix/v3850-license-policy branch August 25, 2026 02:37
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
* fix(deps): keep unused pnpm peers out of production

* docs(changelog): link dependency policy fix to PR 11342
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant