Skip to content

fix: Ignore peer dependencies in package graph - #13025

Merged
anthonyshew merged 5 commits into
vercel:mainfrom
kitten:@kitten/fix/internal-peer-cycle-rejection
Jun 5, 2026
Merged

anthonyshew merged 5 commits into
vercel:mainfrom
kitten:@kitten/fix/internal-peer-cycle-rejection

Conversation

@kitten

@kitten kitten commented Jun 5, 2026 •

Copy link
Copy Markdown
Contributor

Why

Turborepo should not treat peerDependencies as package graph inputs. Peers are supplied by consumers and should not create workspace build-order edges, participate in cycle detection, or influence package graph external dependency metadata.

This fixes a regression where pure peer back-edges could make otherwise valid monorepos fail with circular package dependency errors.

What

  • Ignore peer dependencies during package graph dependency splitting.
  • Preserve normal dependency behavior for dependencies, devDependencies, and optionalDependencies.
  • Add regression coverage for internal peer back-edges and external peer declarations.

How

Run:

cargo test -p turborepo-repository

Manual reproduction:

  1. Create a workspace where app depends on lib and lib declares app only as a peer.
  2. Configure build with dependsOn: ["^build"].
  3. Run turbo run build.

Expected result: Turbo builds lib before app and does not report a package dependency cycle.

@kitten
kitten requested a review from a team as a code owner June 5, 2026 16:51
@kitten
kitten requested review from tknickman and removed request for a team June 5, 2026 16:51
@vercel

vercel Bot commented Jun 5, 2026

Copy link
Copy Markdown
Contributor

@kitten is attempting to deploy a commit to the Vercel Team on Vercel.

A member of the Team first needs to authorize it.

Comment thread crates/turborepo-repository/src/package_graph/builder.rs Outdated
@anthonyshew anthonyshew changed the title fix: Ignore pure peer dependencies in the package graph again fix: Ignore peer dependencies in package graph Jun 5, 2026
@anthonyshew

Copy link
Copy Markdown
Contributor

Hey, thanks for getting this started. I added on a few things and reworked a few more. Will get merged and get you a canary so you can keep trying things.

@anthonyshew
anthonyshew merged commit 40e3e2b into vercel:main Jun 5, 2026
30 of 39 checks passed
@kitten

kitten commented Jun 5, 2026

Copy link
Copy Markdown
Contributor Author

Thank you! 🙏

anthonyshew pushed a commit that referenced this pull request Jun 5, 2026
## Release v2.9.17-canary.4

> [!CAUTION]
> Versioned docs aliasing FAILED. [View
logs](https://github.com/vercel/turborepo/actions/runs/27041297146)

### Changes

- docs: Exclude Next dev output from cache examples (#13019) (`25349a4`)
- release(turborepo): 2.9.17-canary.3 (#13017) (`cb93407`)
- fix: Highlight active docs sidebar item (#13023) (`4e88ddd`)
- fix: Ignore peer dependencies in package graph (#13025) (`40e3e2b`)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
anthonyshew pushed a commit that referenced this pull request Jun 9, 2026
## Release v2.9.17

> [!CAUTION]
> Versioned docs aliasing FAILED. [View
logs](https://github.com/vercel/turborepo/actions/runs/27218228460)

### Changes

- fix: Keep non-PTY stdin alive for persistent tasks (#12972)
(`26ae68b`)
- release(turborepo): 2.9.16 (#12970) (`fac2b75`)
- release(turborepo): 2.9.17-canary.1 (#12973) (`e9a27cc`)
- fix: Add auth HTTP timeouts (#12976) (`787f12c`)
- fix: Detect affected root tasks in query (#12977) (`e7fdf7d`)
- fix: Wait for Windows graceful shutdown (#12979) (`ac6f362`)
- release(turborepo): 2.9.17-canary.2 (#12980) (`14720cc`)
- test: Skip installs for JSON output fixtures (#12981) (`882c19f`)
- feat: Add Rsbuild examples (#12942) (`e533423`)
- test: Skip installs for single package dry runs (#12982) (`8d773db`)
- test: Skip Corepack setup without installs (#12983) (`d8cfabe`)
- test: Skip installs for metadata-only Rust tests (#12985) (`62cae8d`)
- test: Skip remaining unnecessary fixture installs (#12986) (`ed45325`)
- test: Add final hash contract snapshots (#12984) (`1ad2ad5`)
- test: Trim run logging integration matrix (#12987) (`34e89b2`)
- test: Trim affected query integration matrix (#12988) (`8dd1efb`)
- test: Narrow Windows integration test group (#12989) (`b79ef0d`)
- test: Trim task dependency integration coverage (#12990) (`62973fe`)
- test: Trim affected integration coverage (#12991) (`8e094b8`)
- test: Collapse integration test matrices (#12992) (`6446ba6`)
- test: Collapse non-watch integration matrices (#12993) (`691aaf1`)
- test: Collapse summary and caching test setup (#12994) (`410a38a`)
- test: Trim lockfile-aware caching integration matrix (#12995)
(`d11be19`)
- test: Move inference, env, and otel coverage lower (#12996)
(`a0c4666`)
- test: Trim turborepo-scm subprocess tests (#12998) (`f52c18b`)
- test: Remove Windows nextest thread cap (#12999) (`773445f`)
- test: Trim workspace config integration tests (#13000) (`b043ede`)
- test: Trim run logging integration coverage (#13001) (`9cace3e`)
- test: Trim summary inference and single package tests (#13002)
(`1be86c6`)
- test: Trim continue and persistent integration tests (#13004)
(`0a91801`)
- test: Trim force and workspace inheritance tests (#13005) (`cc5b55d`)
- test: Trim SCM regression matrix (#13006) (`468a9dd`)
- test: Trim miscellaneous integration tests (#13007) (`1eeeb97`)
- test: Trim affected and cache integration coverage (#13008)
(`8b86297`)
- refactor: Split engine builder modules (#13009) (`c1cf87a`)
- refactor: Split process child module (#13014) (`24dd7c1`)
- refactor: Split CLI module (#13013) (`7bd8841`)
- refactor: Split Bun lockfile module (#13012) (`659abfc`)
- Fix typo in .gitignore comment (#13010) (`f4f0abd`)
- fix: Preserve Bun nested dependency versions (#13016) (`4db4386`)
- docs: Exclude Next dev output from cache examples (#13019) (`25349a4`)
- release(turborepo): 2.9.17-canary.3 (#13017) (`cb93407`)
- fix: Highlight active docs sidebar item (#13023) (`4e88ddd`)
- fix: Ignore peer dependencies in package graph (#13025) (`40e3e2b`)
- release(turborepo): 2.9.17-canary.4 (#13032) (`0881aa4`)
- fix: Preserve pnpm override-resolved prune deps (#13031) (`8c61dd1`)
- fix: Keep PTY stdin open for tasks (#13033) (`fb28d8a`)
- fix: Add TUI pane padding before logs (#13034) (`08a42f2`)
- fix(api-client): Support P-521 ECDSA certificate chains over rustls
(#13036) (`03359d9`)
- chore: Restore aarch64 musl release builds (#13037) (`40844e9`)
- release(turborepo): 2.9.17-canary.5 (#13038) (`d5bd26c`)
- docs: Remove ESM warning from gen page (#13039) (`1745bed`)
- fix: Bypass npm command shim on Windows (#13040) (`1e6516e`)
- feat: Add JIT task input hashing (#13043) (`026b3da`)
- fix: Defer hashes for JIT task dependents (#13045) (`2332886`)
- release(turborepo): 2.9.17-canary.6 (#13044) (`5550ced`)
- release(turborepo): 2.9.17-canary.7 (#13046) (`7981598`)
- fix: Send Ctrl+C to Windows PTY tasks (#13041) (`e62661a`)

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
anthonyshew pushed a commit that referenced this pull request Jun 24, 2026
## Release v2.10.0

> [!CAUTION]
> Versioned docs aliasing FAILED. [View
logs](https://github.com/vercel/turborepo/actions/runs/28111901682)

### Changes

- fix: Wait for process trees before task completion (#12809)
(`a3b4d94`)
- release(turborepo): 2.9.15-canary.1 (#12810) (`f7b9d3a`)
- ci: Sign macOS release binaries (#12811) (`fe3b84f`)
- release(turborepo): 2.9.15-canary.2 (#12812) (`c34a86b`)
- fix: Prevent cache archive symlink reads (#12813) (`ab90c81`)
- release(turborepo): 2.9.15-canary.3 (#12814) (`d92bfcb`)
- fix: Avoid path-racy chmod during directory restore (#12815)
(`c62c92b`)
- fix: Prevent cache restore symlink race writes (#12817) (`0f167cf`)
- chore: Deny Rust panic extraction by default (#12818) (`958fc4e`)
- fix: Make structured log symlink defense race-safe (#12821)
(`46df4de`)
- fix: Preserve Bun alias child packages (#12822) (`cbfef22`)
- fix: Avoid UTF-8 panics at boundaries (#12823) (`a9b43ba`)
- fix: Preserve non-UTF-8 Git path boundaries (#12826) (`85ba487`)
- fix: Create daemon dirs with private permissions (#12827) (`aca956e`)
- fix: Return Berry lockfile errors instead of panicking (#12828)
(`3fd29a3`)
- fix: Isolate Corepack state in integration tests (#12831) (`f49f23b`)
- ci: Use larger Windows runners for Rust tests (#12832) (`7618d6e`)
- docs: Add `with-vite-module-federation` example (#12794) (`2209f61`)
- test: Run Rust tests without partitioning (#12833) (`e53c512`)
- chore: Remove `TaskHashTracker`-based `expect()` calls (#12836)
(`a10a5fe`)
- chore: Deduplicate hash canonicalization (#12837) (`795a912`)
- fix: Prevent Windows process drain hangs (#12838) (`030f50b`)
- fix: Refactor execsync to execfilesync for Shell command built from
environment values (#12829) (`a410750`)
- test: Bound vt100 random quickcheck (#12839) (`8f9eac2`)
- fix: Validate daemon discovery responses (#12840) (`f3268b2`)
- fix: Store `PackageGraph` root invariants (#12841) (`67d733d`)
- chore: Avoid engine graph node expects (#12842) (`639c535`)
- test: Make Rust tests parallel-safe (#12843) (`dd34c30`)
- fix: Avoid graph utility node lookup panics (#12844) (`8beff2e`)
- fix: Avoid graph walker `expect()` calls (#12845) (`0734316`)
- fix: Remove fs panic extraction lints (#12846) (`d6396de`)
- fix: Remove fixed map panic extraction calls (#12847) (`412dc00`)
- fix: Remove devtools WebSocket panics (#12850) (`2d11941`)
- fix: Remove json rewrite panic lint allow (#12848) (`88709b4`)
- fix: Remove turborepo-types panic lint allows (#12849) (`9d2cda3`)
- chore: Remove turborepo-hash build expect (#12851) (`c271628`)
- fix: Remove napi panic lint allows (#12852) (`9d631fe`)
- fix: Avoid globwatch expect calls (#12853) (`800b355`)
- fix: Remove LSP expect callsites (#12854) (`5a22478`)
- fix: Remove scope panic lint allows (#12855) (`98cacad`)
- fix: Remove task hash panic lints (#12856) (`c727e30`)
- fix: Remove frameworks panic lint allows (#12857) (`6a5e891`)
- fix: Remove microfrontends proxy expect lint allow (#12859)
(`787eee6`)
- fix: Avoid API client expect calls (#12858) (`43d3229`)
- fix: Avoid task executor expect calls (#12860) (`709ebd2`)
- fix: Remove turbo-trace unwrap callsite (#12863) (`23ed3ac`)
- fix: Remove Vercel API mock expect usage (#12862) (`0386df2`)
- fix: Remove vt100 expect lint allow (#12861) (`db1ee55`)
- fix: Remove turborepo-shim expect callsites (#12864) (`6b7c2c7`)
- test: Deflake daemon existing process test (#12865) (`1c57b5b`)
- fix: Avoid repository NAPI unwrap calls (#12866) (`459d1e6`)
- fix: Remove pidlock panic callsites (#12867) (`aacfcc6`)
- fix: Remove telemetry panic callsites (#12868) (`9968f36`)
- chore: Remove Rust re-export shims (#12870) (`0c7b052`)
- fix: Remove turbo-json panic lint allows (#12869) (`3eb13fd`)
- fix: Remove `globwalk`'s `expect()` callsites (#12871) (`ca42137`)
- fix: Remove `turbopath`'s `expect()` callsites (#12872) (`e781dbe`)
- test: Deflake Corepack prepare lock on Windows (#12873) (`53c9b4b`)
- fix: Remove signals panic callsites (#12874) (`b5e3b6d`)
- fix: Remove turbo-trace expect allow (#12876) (`67657e5`)
- fix: Remove Vercel API mock unwrap usage (#12877) (`dd99f86`)
- fix: Remove task executor unwrap usage (#12878) (`f16c120`)
- fix: Remove run summary expect usage (#12879) (`2670768`)
- fix: Remove microfrontends proxy unwrap usage (#12880) (`80da7a6`)
- fix: Remove api client unwrap usage (#12881) (`73f3c1b`)
- fix: Remove globwalk unwrap usage (#12883) (`a058336`)
- fix: Remove UI `expect()` usage (#12882) (`843515e`)
- fix: Remove microfrontends expect usage (#12885) (`91d5ac0`)
- fix: Remove `boundaries`'s `expect()` usage (#12887) (`4ae4b19`)
- fix: Remove `turborepo-process`'s `unwrap()` usage (#12888)
(`7badbb5`)
- fix: Remove UI unwrap usage (#12889) (`8c4316e`)
- fix: Remove microfrontends unwrap allow (#12890) (`26168cd`)
- fix: Remove `turborepo-process`'s `expect()` usage (#12891)
(`f3e8a42`)
- fix: Remove scm expect usage (#12893) (`4c0a0e0`)
- fix: Remove auth unwrap usage (#12886) (`a2eed47`)
- fix: Remove `turbopath`'s `unwrap()` usage (#12884) (`e1f2003`)
- fix: Remove `auth`'s `expect()` usage (#12895) (`d13dee7`)
- fix: Remove wax unwrap usage (#12899) (`04c99fb`)
- fix: Remove scm unwrap usage (#12897) (`715cd2c`)
- fix: Remove `turborepo-boundaries`'s `unwrap()` usage (#12896)
(`4484b36`)
- fix: Remove daemon unwrap usage (#12898) (`643b982`)
- fix: Include lockfile-changed packages in affected tasks (#12900)
(`81cae94`)
- fix: Remove `turborepo-wax`'s `expect()` usage (#12901) (`18816eb`)
- fix: Remove `turborepo-filewatch`'s `expect()` usage (#12903)
(`d1dff11`)
- fix: Remove `turborepo-cache`'s `expect()` usage (#12902) (`ccd358d`)
- fix: Remove `turborepo-daemon`'s `expect()` usage (#12904) (`a9d8836`)
- fix: Remove `turborepo-engine`'s `unwrap()` usage (#12906) (`5262b40`)
- fix: Remove filewatch unwrap usage (#12907) (`364c801`)
- fix: Remove engine expect usage (#12908) (`92ef87c`)
- fix: Remove cache unwrap usage (#12909) (`c08053c`)
- fix: Remove `turborepo-lockfiles` `expect()` usage (#12910)
(`756ae7c`)
- chore: Set pnpm minimum release age (#12912) (`1636a8c`)
- fix: Remove `turborepo-lockfiles`'s `unwrap()` usage (#12911)
(`40f8d8f`)
- fix: Remove `turborepo-vt100`'s `unwrap()` usage (#12913) (`c7482f9`)
- release(turborepo): 2.9.15-canary.4 (#12905) (`9f289d9`)
- fix: Remove `turborepo-lib`'s `unwrap()` usage (#12915) (`a8ce590`)
- fix: Remove `turborepo-lib`'s `expect()` usage (#12914) (`d1745a6`)
- fix: Remove shim test unwrap usage (#12917) (`0d98ca3`)
- fix: Remove turbo json test unwrap allowance (#12918) (`01367e9`)
- fix: Remove run summary test unwrap usage (#12916) (`88745d1`)
- release(turborepo): 2.9.15-canary.5 (#12919) (`b44d419`)
- fix: Restore task completion semantics (#12923) (`1a71128`)
- fix: Preserve nested Bun workspace dependency versions (#12924)
(`a77a0e5`)
- release(turborepo): 2.9.15-canary.6 (#12925) (`f675858`)
- fix: Restore release PR auto-merge (#12927) (`155e672`)
- perf: Index repo gitignore matchers (#12928) (`187a0fd`)
- ci: Disable incremental Rust test builds (#12929) (`8c7dbc6`)
- perf: Trim OpenTelemetry crate features (#12930) (`7f0afe7`)
- perf: Trim microfrontends proxy HTTP features (#12931) (`ac537a8`)
- fix: Accept `experimentalCI` object config (#12934) (`6f662f2`)
- release(turborepo): 2.9.15-canary.7 (#12935) (`0e56cdc`)
- fix: Restore a few internal invariant checks (#12933) (`767a9d4`)
- fix: Improve profile tracing coverage (#12936) (`3063672`)
- fix: Use build-scale OTel duration buckets (#12939) (`6ed6fb0`)
- fix: Preserve pnpm injected peer package entries (#12940) (`31123f4`)
- feat: Add heap allocation profiling (#12943) (`c7ad6f2`)
- release(turborepo): 2.9.15-canary.8 (#12945) (`06e81ea`)
- docs: Correct attribute presence claims in turborepo-otel (#12932)
(`8fc94f3`)
- chore(turbo-codemod): remove duplicate "in" in transforms path comment
(#12948) (`5fa3039`)
- chore: Switch Geist font imports to npm geist package (#12952)
(`ebebf41`)
- fix: Respect root gitignore during prune (#12953) (`f96ccc4`)
- fix: Harden OTEL endpoint validation (#12954) (`076ff97`)
- release(turborepo): 2.9.15 (#12955) (`c85d410`)
- fix: Avoid hanging PTY shutdown (#12958) (`52e81bd`)
- fix: Retry npm tlog publish failures (#12959) (`5317f65`)
- release(turborepo): 2.9.16-canary.1 (#12960) (`2284fa9`)
- fix: Preserve nested Bun dependency versions (#12963) (`8d4eaf8`)
- Revert "fix: Preserve nested Bun dependency versions" (#12964)
(`3b1b6e9`)
- release(turborepo): 2.9.16-canary.2 (#12961) (`5e5b248`)
- fix: Preserve nested Bun dependency versions (#12965) (`7952b46`)
- fix: Don't delete existing `.git` when using `--no-git` flag (#12968)
(`b4aa626`)
- fix: Keep non-PTY stdin alive for persistent tasks (#12972)
(`26ae68b`)
- release(turborepo): 2.9.16 (#12970) (`fac2b75`)
- release(turborepo): 2.9.17-canary.1 (#12973) (`e9a27cc`)
- fix: Add auth HTTP timeouts (#12976) (`787f12c`)
- fix: Detect affected root tasks in query (#12977) (`e7fdf7d`)
- fix: Wait for Windows graceful shutdown (#12979) (`ac6f362`)
- release(turborepo): 2.9.17-canary.2 (#12980) (`14720cc`)
- test: Skip installs for JSON output fixtures (#12981) (`882c19f`)
- feat: Add Rsbuild examples (#12942) (`e533423`)
- test: Skip installs for single package dry runs (#12982) (`8d773db`)
- test: Skip Corepack setup without installs (#12983) (`d8cfabe`)
- test: Skip installs for metadata-only Rust tests (#12985) (`62cae8d`)
- test: Skip remaining unnecessary fixture installs (#12986) (`ed45325`)
- test: Add final hash contract snapshots (#12984) (`1ad2ad5`)
- test: Trim run logging integration matrix (#12987) (`34e89b2`)
- test: Trim affected query integration matrix (#12988) (`8dd1efb`)
- test: Narrow Windows integration test group (#12989) (`b79ef0d`)
- test: Trim task dependency integration coverage (#12990) (`62973fe`)
- test: Trim affected integration coverage (#12991) (`8e094b8`)
- test: Collapse integration test matrices (#12992) (`6446ba6`)
- test: Collapse non-watch integration matrices (#12993) (`691aaf1`)
- test: Collapse summary and caching test setup (#12994) (`410a38a`)
- test: Trim lockfile-aware caching integration matrix (#12995)
(`d11be19`)
- test: Move inference, env, and otel coverage lower (#12996)
(`a0c4666`)
- test: Trim turborepo-scm subprocess tests (#12998) (`f52c18b`)
- test: Remove Windows nextest thread cap (#12999) (`773445f`)
- test: Trim workspace config integration tests (#13000) (`b043ede`)
- test: Trim run logging integration coverage (#13001) (`9cace3e`)
- test: Trim summary inference and single package tests (#13002)
(`1be86c6`)
- test: Trim continue and persistent integration tests (#13004)
(`0a91801`)
- test: Trim force and workspace inheritance tests (#13005) (`cc5b55d`)
- test: Trim SCM regression matrix (#13006) (`468a9dd`)
- test: Trim miscellaneous integration tests (#13007) (`1eeeb97`)
- test: Trim affected and cache integration coverage (#13008)
(`8b86297`)
- refactor: Split engine builder modules (#13009) (`c1cf87a`)
- refactor: Split process child module (#13014) (`24dd7c1`)
- refactor: Split CLI module (#13013) (`7bd8841`)
- refactor: Split Bun lockfile module (#13012) (`659abfc`)
- Fix typo in .gitignore comment (#13010) (`f4f0abd`)
- fix: Preserve Bun nested dependency versions (#13016) (`4db4386`)
- docs: Exclude Next dev output from cache examples (#13019) (`25349a4`)
- release(turborepo): 2.9.17-canary.3 (#13017) (`cb93407`)
- fix: Highlight active docs sidebar item (#13023) (`4e88ddd`)
- fix: Ignore peer dependencies in package graph (#13025) (`40e3e2b`)
- release(turborepo): 2.9.17-canary.4 (#13032) (`0881aa4`)
- fix: Preserve pnpm override-resolved prune deps (#13031) (`8c61dd1`)
- fix: Keep PTY stdin open for tasks (#13033) (`fb28d8a`)
- fix: Add TUI pane padding before logs (#13034) (`08a42f2`)
- fix(api-client): Support P-521 ECDSA certificate chains over rustls
(#13036) (`03359d9`)
- chore: Restore aarch64 musl release builds (#13037) (`40844e9`)
- release(turborepo): 2.9.17-canary.5 (#13038) (`d5bd26c`)
- docs: Remove ESM warning from gen page (#13039) (`1745bed`)
- fix: Bypass npm command shim on Windows (#13040) (`1e6516e`)
- feat: Add JIT task input hashing (#13043) (`026b3da`)
- fix: Defer hashes for JIT task dependents (#13045) (`2332886`)
- release(turborepo): 2.9.17-canary.6 (#13044) (`5550ced`)
- release(turborepo): 2.9.17-canary.7 (#13046) (`7981598`)
- fix: Send Ctrl+C to Windows PTY tasks (#13041) (`e62661a`)
- release(turborepo): 2.9.17 (#13047) (`7dd54b7`)
- ci: Fetch version.txt via API in docs alias failure notification
(#13050) (`7d361a4`)
- fix: Harden cache archive symlink restore (#13051) (`403a355`)
- chore: Remove web UI mode (#13052) (`8cff6d5`)
- fix: Harden query server file access (#13053) (`2a2bc5c`)
- fix: Confine prune patch paths (#13054) (`7f353ca`)
- fix: Prevent git argument injection in SCM refs (#13055) (`f46f896`)
- fix: Strip special mode bits from cache restore (#13056) (`92e1f8e`)
- fix: Contain incremental cache outputs (#13057) (`16dc881`)
- fix(turborepo): Normalize Windows daemon path hash (#13020)
(`24e2d34`)
- fix: Preserve vt100 cell byte counts (#13058) (`34514e2`)
- fix: Separate artifact signature fields (#13059) (`3018717`)
- fix: Validate OidHash hex buffers (#13060) (`da8e348`)
- fix: Block self-hosted login URLs from attempting to use Vercel's SSO
(#13061) (`2a76556`)
- release(turborepo): 2.9.18 (#13062) (`912e7eb`)
- fix: Re-authenticate when stored token loses access to linked team
(#13064) (`0afbf1e`)
- release(turborepo): 2.9.19-canary.1 (#13065) (`689d579`)
- fix: Stop shim from killing local turbo on Windows Ctrl+C (#13067)
(`0a341ae`)
- release(turborepo): 2.9.19-canary.2 (#13068) (`b62a04b`)
- ci: Add PR workflow timeouts (#13070) (`539c17e`)
- fix: Deliver Ctrl-C to ConPTY children during graceful shutdown on
Windows (#13069) (`ca712ab`)
- release(turborepo): 2.9.19-canary.3 (#13071) (`6a2f50c`)
- fix: Use PTY for interactive Windows tasks (#13073) (`b95ebda`)
- fix: Filter pruned pnpm workspace patches (#13075) (`de378a5`)
- fix: Cache outputs through internal symlinks (#13076) (`823faea`)
- fix: Prevent ConPTY cursor query output (#13077) (`4e85349`)
- release(turborepo): 2.9.19-canary.4 (#13074) (`ba5394a`)
- release(turborepo): 2.9.19-canary.5 (#13079) (`a42ea25`)
- fix: Preserve PNPM deps check config (#13084) (`57ddec6`)
- fix: Speed up default create-turbo download (#13085) (`fc2bebc`)
- fix: Preserve pnpm peer-resolved prune entries (#13086) (`d13698f`)
- fix: Precompute unblocked JIT descendants (#13088) (`ce4324f`)
- fix: Use repo package manager for generate (#13089) (`a562e78`)
- fix: Handle Windows package manager shutdown (#13090) (`b6ab687`)
- release(turborepo): 2.9.19-canary.6 (#13092) (`90b843f`)
- fix: Prevent duplicate PTY graceful shutdown signals (#13093)
(`e49085f`)
- fix: Remove accidental shell commands example changes (#13094)
(`bc11507`)
- release(turborepo): 2.9.19-canary.7 (#13095) (`79d597b`)
- fix: Refine graceful shutdown messaging (#13098) (`79b18b2`)
- fix: Gracefully stop nested PTY processes (#13100) (`c57ffe6`)
- fix: Restore TUI force shutdown (#13102) (`ab32c2b`)
- release(turborepo): 2.9.19-canary.8 (#13103) (`fbad2e5`)
- fix: Upgrade tsdown in kitchen-sink api to fix dev script (#13105)
(`54504ec`)
- fix: Soften force shutdown message (#13104) (`b09dad1`)
- fix: Thread `allow_no_package_manager` to daemon and watcher (#13091)
(`95da5c5`)
- fix: Preserve bun patchedDependencies during prune (#13106)
(`c6e28f2`)
- fix: Ignore symlink cycles when caching outputs (#13107) (`d1f32a3`)
- release(turborepo): 2.9.19-canary.9 (#13108) (`f2ca090`)
- fix: Preserve terminal settings for child PTYs (#13110) (`fe55e56`)
- fix: Upgrade esbuild to patched version (#13112) (`157c3b8`)
- fix(prune): Relocate stranded transitive deps when promoting npm
workspace-nested packages (#13111) (`0938cb9`)
- Update Next.js version to 16.2.5 (#13081) (`8f89a09`)
- fix: Add ComSpec and PATHEXT to default Windows env passthrough
(#13114) (`6988692`)
- fix: Respect task inputs when stopping interruptible persistent tasks
in watch (#13116) (`0220b35`)
- docs: Fix stderr debugging guidance (#13122) (`517e1a5`)
- feat: Add deferred hashing for task inputs (#13125) (`4ebb50f`)
- fix: Restart deferred hash consumers in watch (#13127) (`6dccf5a`)
- chore: Update to Rust 1.96.0 (#12974) (`75ee2cc`)
- fix: Improve watch graceful shutdown (#13128) (`5ba8917`)
- fix: Hash selected dependency outputs instead of tasks (#13129)
(`65175fe`)
- release(turborepo): 2.9.19-canary.10 (#13130) (`a12323b`)

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
leoisadev1 added a commit to opencoredev/email-sdk that referenced this pull request Jul 6, 2026
…o 2.10

Turbo >=2.9.17 ignores peerDependencies when building the package graph
(vercel/turborepo#13025), so convex-email's @opencoredev/email-sdk peer
range stopped scheduling email-sdk#build before the convex-email tests
and CI failed with 'Cannot find module @opencoredev/email-sdk'. Make
the workspace edge explicit with a workspace:* devDependency (dev-only,
published package unchanged) and document the invariant in AGENTS.md.

Generated-By: PostHog Code
Task-Id: ec2538f2-5c80-4142-b4b3-b1a53394862e
leoisadev1 added a commit to opencoredev/email-sdk that referenced this pull request Jul 6, 2026
)

* chore(deps): refresh in-range dependencies to latest safe versions

* fix(docs): handle nullable markdown from @usenotra/sdk 1.3.x

@usenotra/sdk 1.3.1 changed ListPostsPost.markdown from string to
string | null: image-type posts have no Markdown body (their content is
a CDN image URL). Model that in NotraPostInput and skip such posts in
mapNotraPost — the blog can only render Markdown bodies. Adds a test.

Generated-By: PostHog Code
Task-Id: ec2538f2-5c80-4142-b4b3-b1a53394862e

* fix(ci): restore convex-email test -> email-sdk build edge under turbo 2.10

Turbo >=2.9.17 ignores peerDependencies when building the package graph
(vercel/turborepo#13025), so convex-email's @opencoredev/email-sdk peer
range stopped scheduling email-sdk#build before the convex-email tests
and CI failed with 'Cannot find module @opencoredev/email-sdk'. Make
the workspace edge explicit with a workspace:* devDependency (dev-only,
published package unchanged) and document the invariant in AGENTS.md.

Generated-By: PostHog Code
Task-Id: ec2538f2-5c80-4142-b4b3-b1a53394862e

---------

Co-authored-by: tembo[bot] <208362400+tembo[bot]@users.noreply.github.com>
Co-authored-by: Leo <108278866+leoisadev1@users.noreply.github.com>
whysosuresh added a commit to stigmer/stigmer that referenced this pull request Sep 10, 2026
…ld graph sees them

@stigmer/sdk, @stigmer/react and @stigmer/ink reach @stigmer/protos (and
@stigmer/sdk) only through peerDependencies. Their tsc reads protos'
dist/*.d.ts, so today they build only because build:libs is one serial
line with protos first. Turborepo does not treat peers as workspace edges
(vercel/turborepo#13025), so before this change `turbo run build
--filter=@stigmer/sdk` scheduled @stigmer/sdk#build alone; after it, the
dry run lists @stigmer/protos#build first for all three packages.

Same pattern #1045 used for sdk/react's optional peers: a package's
devDependencies name what its own build and tests need. publish-libs.mjs
copies only dependencies and peerDependencies into dist/package.json, so
the published manifests do not change; the tarball parity capture against
the Stage B baseline is identical.

Lockfile: five workspace-entry lines added, no resolved version moved.
Co-authored-by: Cursor <cursoragent@cursor.com>
whysosuresh added a commit to stigmer/stigmer that referenced this pull request Sep 10, 2026
…04) (#1046)

* build(repo): npm is the workspace's one package manager; the clean-room typecheck resolves with npm

Stage B (Turborepo adoption) of stigmer-cloud project 20260904.04, B1.

The root package.json declared packageManager yarn@3.8.7 while every
install and publish path used npm against package-lock.json. Turborepo 2
hashes the lockfile that declaration implies, so the field had to be
made truthful before turbo.json exists: packageManager is now npm@10.9.4,
the npm bundled with the Node in .nvmrc. Corepack refuses a stray yarn at
the root with a clear message; site/ keeps its own yarn@4.5.1 and every
call into it is already cd site && yarn.

Removed with it: the yarn-only resolutions block (npm reads overrides,
which already carries the same two pins; npm workspaces resolve siblings
natively, so the workspace:* self-pins had no npm meaning); .yarnrc.yml
(its one hint injected a peer yarn would not auto-install and npm does);
the .gitignore lines for a root yarn.lock and .yarn/ (a stray one should
now show as untracked).

ci.ts-sdk's clean-room job installs with npm and the tracked lockfile
removed, the same lockfile-free re-resolve it did under yarn, honoring
overrides instead of resolutions. Its header records the two semantic
differences: npm fails a conflicting peer with ERESOLVE where yarn
warned, and npm hoists sibling workspaces' dependencies where yarn did
not, so the class the yarn job last caught (#1044) is invisible here and
belongs to each package's devDependencies.

Publish parity: node scripts/publish-libs.mjs --version 0.0.0-parity
--skip-build --dry-run produces the same shasum for all 11 packages
before and after this change (baseline captured twice at 400dda2,
byte-identical; recorded in the project's evidence/).

Co-authored-by: Cursor <cursoragent@cursor.com>

* build(sdk): declare the workspace peers as devDependencies so the build graph sees them

@stigmer/sdk, @stigmer/react and @stigmer/ink reach @stigmer/protos (and
@stigmer/sdk) only through peerDependencies. Their tsc reads protos'
dist/*.d.ts, so today they build only because build:libs is one serial
line with protos first. Turborepo does not treat peers as workspace edges
(vercel/turborepo#13025), so before this change `turbo run build
--filter=@stigmer/sdk` scheduled @stigmer/sdk#build alone; after it, the
dry run lists @stigmer/protos#build first for all three packages.

Same pattern #1045 used for sdk/react's optional peers: a package's
devDependencies name what its own build and tests need. publish-libs.mjs
copies only dependencies and peerDependencies into dist/package.json, so
the published manifests do not change; the tarball parity capture against
the Stage B baseline is identical.

Lockfile: five workspace-entry lines added, no resolved version moved.
Co-authored-by: Cursor <cursoragent@cursor.com>

* build(repo): the TS workspace runs through a Turborepo task graph (B2, B3)

turbo.json declares the graph the root scripts used to spell out by hand:
build depends on ^build and caches dist/**; typecheck and test depend on
^build (the protos and backend libs export compiled .d.ts); lint is
type-unaware and free; clean is never cached. Package-specific contracts
stay in the same file: web's Next export outputs, desktop's Tauri env
inputs, the two SDK suites whose fixtures live outside their package
($TURBO_ROOT$ inputs), and the conformance and e2e suites that are never
cached because their result belongs to the infrastructure they ran against.
The B3 boundary is written in its header: the workspace members are turbo's
world; runner, stigmer-server, site, extension-consumer and the examples
stay standalone. cacheDir is explicit so a worktree never writes its cache
into the primary checkout (turbo shares a git worktree's cache through the
main worktree by default).

The four root scripts call scripts/turbo-set.mjs <set> <task>, which
resolves `libs` from publish-libs.mjs's PACKAGES (the verify-esm-node
precedent) and `runner-deps` from the runner's and server's file: links,
adds --concurrency=1 for `libs test` (today's serial behavior), switches
Turborepo telemetry off (owner ruling D3) and forwards any extra flags.
Their callers (Makefile, CI, publish-libs.mjs) see the same names.

turbo is pinned exact at 2.10.12; .turbo joins .gitignore and .dockerignore.

Tests (all wired into root `npm test`):
- turbo-set.test.mjs: set resolution, flag shaping, telemetry env.
- turbo-graph.test.mjs: from turbo's own dry run, every workspace @stigmer/*
  a publishable package declares is a #build it waits on (the peer-only
  regression), and every build caches dist/** in strict env mode.
- turbo-inputs.test.mjs: every out-of-package path a suite reads is in
  turbo's resolved input hash for that suite (the stale-cached-pass hole).
- publish-libs.test.mjs: PACKAGES is exactly the non-private workspace
  members, both directions.

Measured on this tree: cold build:libs 44s (was ~62s serial), peak
process-tree RSS 1.72 GB; publish dry-run tarballs byte-identical to the
Stage B baseline cold, warm (cache-restored after clean) and after two
FULL TURBO runs; npm test passes the same 6926 tests per package; web and
desktop builds hit cache on their second run.

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs(sdk): the TypeScript loop runs from the workspace root through Turborepo

The Requirements section still opened with `cd typescript/ && npm install`,
a recipe from before the root workspace. It now shows the root loop
(npm ci, build:libs, test, a per-package typecheck), says what the turbo
cache does and how to bypass or clear it, and states the telemetry policy.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants