Skip to content

chore(deps): bump pnpm to 11.3.0#24

Merged
xdanger merged 1 commit into
mainfrom
codex/dependency-sweep-20260526-taptap-github
May 26, 2026
Merged

chore(deps): bump pnpm to 11.3.0#24
xdanger merged 1 commit into
mainfrom
codex/dependency-sweep-20260526-taptap-github

Conversation

@xdanger
Copy link
Copy Markdown
Member

@xdanger xdanger commented May 26, 2026

Summary

  • bump the checked-in packageManager pin from pnpm@11.2.2 to pnpm@11.3.0
  • leave pnpm-lock.yaml unchanged because the frozen install stayed current

Verification

  • corepack pnpm install --frozen-lockfile
  • corepack pnpm run lint
  • corepack pnpm outdated --format json -> {}

Risk

  • low: pnpm@11.3.0 keeps the same Node floor (>=22.13), while this repo requires Node >=22.22.1 and was validated on Node 24.16.0.

- 🔧 keep package-manager pin current without lockfile churn
@claude
Copy link
Copy Markdown

claude Bot commented May 26, 2026

✅ Approved

Scope: Single-line packageManager pin bump from pnpm@11.2.2pnpm@11.3.0 with updated SHA-512 hash in package.json.

No new findings. This is a minimal, low-risk dependency version bump with no lockfile churn and no code changes. CI static analysis checks are passing.

Copy link
Copy Markdown

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the repository’s Corepack packageManager pin to use pnpm@11.3.0, keeping the toolchain version consistent for installs and scripts.

Changes:

  • Bump packageManager from pnpm@11.2.2 to pnpm@11.3.0 (with updated integrity hash).

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@greptile-apps
Copy link
Copy Markdown

greptile-apps Bot commented May 26, 2026

Greptile Summary

package.json 中的 packageManager pin 从 pnpm@11.2.2 升级至 pnpm@11.3.0,并同步更新 SHA512 完整性哈希。pnpm 11.3 于 2026-05-24 正式发布,Node.js 最低要求保持 >=22.13,与本仓库的 >=22.22.1 约束完全兼容。

  • 仅修改 package.json 中的 packageManager 字段,pnpm-lock.yaml 保持不变(frozen install 通过验证)。
  • pnpm 11.3.0 主要新增 --skip-manifest-obfuscation 标志(用于 pack/publish),无破坏性变更。

Confidence Score: 5/5

该变更仅修改 packageManager 版本 pin 及其 SHA512 哈希,风险极低,可安全合入。

改动范围仅限 package.json 一行,pnpm 11.3.0 已于 2026-05-24 正式发布,节点兼容性与现有约束无冲突,frozen lockfile 验证通过,无破坏性变更。

无需特别关注的文件。

Important Files Changed

Filename Overview
package.json packageManager 字段从 pnpm@11.2.2 升级至 pnpm@11.3.0,同时更新对应的 SHA512 校验哈希值,无其他改动。

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
    A["开发者运行 corepack pnpm install"] --> B{"corepack 读取 packageManager 字段"}
    B --> C["验证 SHA512 哈希\npnpm@11.3.0"]
    C --> D{"哈希匹配?"}
    D -- 是 --> E["下载 / 使用缓存的 pnpm 11.3.0"]
    D -- 否 --> F["安装失败,拒绝继续"]
    E --> G["--frozen-lockfile 安装依赖"]
    G --> H["pnpm run lint 通过"]
    H --> I["✅ 升级完成"]
Loading

Reviews (1): Last reviewed commit: "🔧 chore(deps): bump pnpm to 11.3.0" | Re-trigger Greptile

@xdanger xdanger merged commit 48e133b into main May 26, 2026
6 checks passed
@xdanger xdanger deleted the codex/dependency-sweep-20260526-taptap-github branch May 26, 2026 08:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants