fix: Preserve pnpm node@runtime: lockfile entries - #13408
Merged
Merged
Conversation
Co-Authored-By: Anthony Shew <anthonyshew@gmail.com>
Contributor
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
tknickman
approved these changes
Jul 20, 2026
node@runtime: lockfile entriesnode@runtime: lockfile entries
anthonyshew
pushed a commit
that referenced
this pull request
Jul 21, 2026
## Release v2.10.6-canary.5 > [!CAUTION] > Versioned docs aliasing FAILED. [View logs](https://github.com/vercel/turborepo/actions/runs/29859795408) ### Changes - docs: Update Geistdocs to 1.13.0 (#13412) (`b1d8c9f`) - release(turborepo): 2.10.6-canary.4 (#13401) (`90eba05`) - fix: Preserve pnpm `node@runtime:` lockfile entries (#13408) (`4ac2f47`) - chore: Fix typos in with-solid example and globwatch comment (#13416) (`424cabd`) - refactor: Remove unused public APIs found by Hawk (#13420) (`831990d`) - fix: Check dynamic imports in boundaries (#13418) (`31be2b8`) - refactor: Use regex! for static pattern compilation (#13419) (`82cd34c`) - fix: Refactor `turbo watch` (#13423) (`328b99f`) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
anthonyshew
pushed a commit
that referenced
this pull request
Jul 22, 2026
## Release v2.10.6 > [!CAUTION] > Versioned docs aliasing FAILED. [View logs](https://github.com/vercel/turborepo/actions/runs/29930611207) ### Changes - release(turborepo): 2.10.5 (#13368) (`a6a563a`) - fix: Disable unresolved Cargo artifact caching (#13362) (`d76aa27`) - fix: Surface create-turbo Git failures (#13371) (`8a8b133`) - fix: Resolve exact cargo profile outputs (#13366) (`0e6a99b`) - fix: Prune Bun production workspace dev dependencies (#13369) (`fee6b66`) - fix: Resolve Cargo target output layouts (#13370) (`8c097cd`) - release(turborepo): 2.10.6-canary.1 (#13374) (`d0dca26`) - fix: Preserve Yarn Babel extension during pruning (#13373) (`02ef828`) - feat: Support Cargo-only repos (#13378) (`24dc68e`) - fix: Preserve colors in TUI output (#13381) (`99c9ffb`) - feat: Infer Cargo workspace tasks (#13380) (`58fe9df`) - fix: Retain shutdown signals for force exit (#13382) (`62ecdaa`) - release(turborepo): 2.10.6-canary.2 (#13383) (`8035b5d`) - fix: Resolve weekly security audit vulnerabilities (#13358) (`64f4aac`) - chore: Update to Rust 1.97.0 (#13322) (`feb0a1a`) - fix: Pin VS Code extension macOS runners (#13391) (`26169cd`) - release(turborepo): 2.10.6-canary.3 (#13392) (`f753f04`) - docs: Add Experimental Rust Guide (#13375) (`a2bf8a2`) - ci: Use affected filtering for JS tests (#13386) (`0536a70`) - ci: Fold docs checks into quality (#13385) (`fcd1858`) - ci: Verify schemas through Turborepo (#13387) (`66551bc`) - chore: Avoid duplicate N-API Cargo build (#13388) (`4ddacf4`) - chore: Hash embedded frameworks data in Rust builds (#13389) (`373c0a2`) - ci: Include VS Code extension type checks (#13390) (`716ad9c`) - refactor: Run releaser bundle directly (#13393) (`b6a92de`) - refactor: Move release publishing into releaser (#13394) (`e0cf33c`) - refactor: Consolidate release orchestration (#13395) (`51f5529`) - feat: Add crate-scoped Cargo verification tasks (#13398) (`aeb2ee5`) - fix: Fetch release commit parent (#13400) (`ab05127`) - docs: Update Geistdocs to 1.13.0 (#13412) (`b1d8c9f`) - release(turborepo): 2.10.6-canary.4 (#13401) (`90eba05`) - fix: Preserve pnpm `node@runtime:` lockfile entries (#13408) (`4ac2f47`) - chore: Fix typos in with-solid example and globwatch comment (#13416) (`424cabd`) - refactor: Remove unused public APIs found by Hawk (#13420) (`831990d`) - fix: Check dynamic imports in boundaries (#13418) (`31be2b8`) - refactor: Use regex! for static pattern compilation (#13419) (`82cd34c`) - fix: Refactor `turbo watch` (#13423) (`328b99f`) - release(turborepo): 2.10.6-canary.5 (#13424) (`ceee06b`) - chore: Upgrade brace-expansion (#13429) (`d45bf2a`) - chore: Update tar to 7.5.18 (#13428) (`d0dbd5a`) - chore: Upgrade js-yaml (#13427) (`c8e36ad`) - fix: Match JIT inputs for affected tasks (#13426) (`1b95fcb`) - fix: Preserve project Yarn package extensions (#13425) (`f08f35c`) --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes #13403.
When a project uses pnpm's
devEngines.runtimewithonFail: "download"(pnpm 10.14+), pnpm records the Node.js runtime in the lockfile as a synthetic dependency: an importer reference plus anode@runtime:<version>entry inpackages:andsnapshots:.turbo prunekept the importer reference but dropped the correspondingpackages:/snapshots:entries, producing an internally inconsistent pruned lockfile.pnpm install --frozen-lockfilein the pruned output then failed with:The root cause was twofold, matching the issue's analysis:
Closure walk dropped the entries. The
runtime:dependency is synthesized by pnpm and is not part of turbo's package graph, so it never appears in the resolved closure passed tosubgraph. The importer reference was preserved, but the package/snapshot entries were not retained.subgraphnow walks importer dependencies using theruntime:protocol (including the root importer, whose regular deps are otherwise sourced from the closure) and retains theirpackages:/snapshots:entries.variantswere stripped on re-serialization.PackageResolutiononly modeled tarball/directory/git fields with no catch-all, so thevariantsarray of atype: variationsresolution — which nests full per-platform binary resolutions — would be lost even if the entry were kept. Added a flattenedotheropaque passthrough (mirroring the existing pattern onPackageSnapshot), and updated the fast parser'sparse_resolutionto capture unknown fields into it instead of skipping them, keeping the fast and serde paths consistent.Testing
test_runtime_resolution_variants_round_trip— verifies thetype: variationsresolution and its nestedvariantslist survive a parse → serialize → parse round-trip.test_subgraph_preserves_runtime_package_and_snapshot— verifiesturbo prunekeepsnode@runtime:22.0.0in bothpackages:andsnapshots:alongside the importer reference.zkochan/repro-turbo-prune-runtime: after pruning,node@runtimeappears in bothpackages:andsnapshots:, and all 12 platform variants (including thelibc: musltarget) are preserved.turborepo-lockfilessuite passes (263 tests);cargo clippyandcargo fmtclean.