Compare commits

..
Author SHA1 Message Date
Zoltan Kochan a53b19ac67 style: remove updater narrative comments 2026-09-04 17:23:12 +02:00
Zoltan Kochan c49a02e6a4 fix: use native bootstrap only for pnpm 12
Route pnpm 12-only versions and ranges through the plain pnpm native package while preserving the existing Node and @pnpm/exe bootstrap paths for older releases.
2026-09-04 17:17:58 +02:00
Zoltan Kochan fedb8a2d14 fix: keep bootstrap updates on pnpm 12
Handle npm's array-shaped view output and resolve only pnpm 12 distribution tags.
2026-09-04 17:10:06 +02:00
Zoltan Kochan 9266926192 refactor: use pnpm 12 native bootstrap
Install the plain pnpm v12 package as the single native bootstrap, remove the legacy @pnpm/exe lockfile and runtime path, and retain the standalone input as a no-op for workflow compatibility.
2026-09-04 17:06:02 +02:00
Zoltan Kochan ae5824b5de feat: support pnpm v12
Approve the pinned @pnpm/exe install script for npm 12, add pnpm 12 coverage across supported runner platforms, and clarify that action-setup remains supported alongside pnpm/setup.
2026-09-04 17:00:44 +02:00
Eric NemchikandGitHub 0977fd9972 docs: Update README to include devEngines.packageManager (#273)
Support added in #211 and #256
2026-08-03 13:44:13 +02:00
48261aca05 fix: update pnpm to v11.19.0 (#283)
* fix: update pnpm to v11.19.0

Via `scripts/update-bootstrap.mjs 11.19.0`

Co-authored-by: Claude Sonnet 5 <jamie.tanna+claude-code@mend.io>

* fixup! fix: update pnpm to v11.19.0

As it needs to be rebuilt on Linux.

---------

Co-authored-by: Claude Sonnet 5 <jamie.tanna+claude-code@mend.io>
2026-08-03 11:54:52 +02:00
Jamie TannaandGitHub 75677f717d ci: use pnpm 11 for pr-check (#284)
Noticed while working on #283.
2026-08-03 11:02:17 +02:00
SukkaandGitHub 769ae71fb3 refactor: introduce restore keys for cache (#280) 2026-08-03 10:32:23 +02:00
Kevin CuiandGitHub 6fed91f804 docs(README): point users to the successor pnpm/setup action (#282)
* docs(README): point users to the successor pnpm/setup action

The pnpm setup action has moved to `pnpm/setup`, which installs
pnpm v11+ as a self-contained native executable and can install a
JavaScript runtime (Node.js, Bun, or Deno) in the same step,
replacing `actions/setup-node`.

Add a notice at the top of the README, a migration section with a
before/after workflow example and an input/output mapping table,
and mention the successor in the Notes section. The rest of the
docs stay intact since `pnpm/action-setup` remains the way to
install pnpm v10 and older.

Signed-off-by: Kevin Cui <bh@bugs.cc>

* docs(README): address review feedback on migration section

Add an explicit version: 11 to the migration example and note when the
input can be omitted, since pnpm/setup requires pnpm v11+ and a repo
migrating from version: 10 may have no packageManager field or one that
pins v10.

Move the v2 upgrade warning below the page title so the two callouts
are no longer adjacent blockquotes (markdownlint MD028), keeping the
successor notice and the legacy warning as separate blocks.

Fix the comma splice and use "set up" as the verb in the Notes
section.

Signed-off-by: Kevin Cui <bh@bugs.cc>

---------

Signed-off-by: Kevin Cui <bh@bugs.cc>
2026-08-02 22:56:56 -04:00
Zoltan KochanandGitHub 0ebf47130e fix: update pnpm to v11.7.0 (#267)
* fix: update pnpm to v11.7.0

* fix: update bundle
2026-06-15 14:04:13 +02:00
13 changed files with 539 additions and 248 deletions
+1 -1
View File
@@ -19,7 +19,7 @@ jobs:
uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5.0.0
with:
run_install: true
version: 9
version: 11
- name: Update dist/index.js
run: pnpm run build
+33 -5
View File
@@ -27,6 +27,12 @@ jobs:
- name: 'ubuntu / v10.33.0'
os: ubuntu-latest
version: '10.33.0'
- name: 'ubuntu / v11.25.0'
os: ubuntu-latest
version: '11.25.0'
- name: 'ubuntu / v12.3.4'
os: ubuntu-latest
version: '12.3.4'
- name: 'ubuntu / v9.15.5 / custom-dest'
os: ubuntu-latest
version: '9.15.5'
@@ -34,9 +40,15 @@ jobs:
- name: 'macos / v9.15.5'
os: macos-latest
version: '9.15.5'
- name: 'macos / v12.3.4'
os: macos-latest
version: '12.3.4'
- name: 'windows / v9.15.5'
os: windows-latest
version: '9.15.5'
- name: 'windows / v12.3.4'
os: windows-latest
version: '12.3.4'
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
@@ -166,26 +178,42 @@ jobs:
shell: bash
standalone:
name: Standalone mode
name: 'Native pnpm bootstrap (npm 12)'
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
with:
persist-credentials: false
- name: Run the action
- uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6
with:
node-version: 26
- name: Use npm 12
run: |
npm install --global npm@12.0.2
test "$(npm --version)" = "12.0.2"
- id: pnpm
name: Run the action
uses: ./
with:
version: 9.15.0
version: 12
standalone: true
- name: 'Test: pnpm works'
env:
PNPM_DEST: ${{ steps.pnpm.outputs.dest }}
run: |
set -e
test -x "$PNPM_DEST/node_modules/pnpm/pnpm"
test ! -d "$PNPM_DEST/node_modules/@pnpm/exe"
which pnpm
actual="$(pnpm --version)"
if [ "${actual}" != "9.15.0" ]; then
echo "Expected 9.15.0, got ${actual}"
if [ "${actual}" != "12.3.4" ]; then
echo "Expected 12.3.4, got ${actual}"
exit 1
fi
mkdir /tmp/test-standalone
+61 -9
View File
@@ -1,18 +1,70 @@
> ## :warning: Upgrade from v2!
> [!IMPORTANT]
> **This action supports pnpm v12 and earlier.**
>
> The v2 version of this action [has stopped working](https://github.com/pnpm/action-setup/issues/135) with newer Node.js versions. Please, upgrade to the latest version to fix any issues.
> For pnpm v11 and newer, [`pnpm/setup`](https://github.com/pnpm/setup) is also available. It downloads pnpm's self-contained release binary (no Node.js or npm required) and can install a JavaScript runtime (Node.js, Bun, or Deno) in the same step, replacing `actions/setup-node` when its feature set fits your workflow.
>
> You can continue using `pnpm/action-setup` with `actions/setup-node`, including for pnpm v11 and v12. See [Using pnpm/setup instead](#using-pnpmsetup-instead) below if you want a single action to install pnpm and a JavaScript runtime.
>
> `pnpm/setup` cannot install pnpm v11 on Intel macOS (`darwin-x64`), where no standalone pnpm v11 binary is published. On that platform, run `actions/setup-node` with Node.js 22.13 or newer before `pnpm/action-setup`, or upgrade to pnpm v12.
# Setup pnpm
Install pnpm package manager.
> ## :warning: Upgrade from v2!
>
> The v2 version of this action [has stopped working](https://github.com/pnpm/action-setup/issues/135) with newer Node.js versions. Please, upgrade to the latest version to fix any issues.
## Using pnpm/setup instead
[`pnpm/setup`](https://github.com/pnpm/setup) installs pnpm v11+ as a native standalone executable and can install Node.js, Bun, or Deno in the same step, so a typical workflow no longer needs `actions/setup-node` or an explicit `pnpm install` step:
```yaml
steps:
- uses: actions/checkout@v6
# Before:
# - uses: pnpm/action-setup@v6
# with:
# version: 10
# cache: true
# - uses: actions/setup-node@v4
# with:
# node-version: 22
# - run: pnpm install
# After:
- uses: pnpm/setup@v1
with:
version: 11
runtime: node@22
cache: true
```
The `version` input can be omitted only when `packageManager` (or `devEngines.packageManager`) in `package.json` declares pnpm v11 or newer; otherwise keep it explicit, since `pnpm/setup` requires pnpm v11+.
Input and output changes:
| `pnpm/action-setup` | `pnpm/setup` | Notes |
| ------------------- | ------------ | ----- |
| `version` | `version` | Must resolve to pnpm v11 or newer. As before, it can be omitted when `packageManager` (or `devEngines.packageManager`) is set in `package.json`. |
| `dest` | `dest` | Unchanged. |
| `run_install` | `install` | `pnpm/setup` runs `pnpm install` automatically when a `package.json` is present (`install: true` by default); set `install: false` to skip it. The object/array form (`recursive`, `cwd`, `args`) is not supported — run those commands in separate steps. |
| `cache` | `cache` | Unchanged. |
| `cache_dependency_path` | `cache-dependency-path` | Renamed to kebab-case. |
| `package_json_file` | `package-json-file` | Renamed to kebab-case. |
| `standalone` | removed | `pnpm/setup` always installs the standalone native executable. |
| n/a | `runtime` | New: installs Node.js, Bun, or Deno (e.g. `node@22`, `bun@latest`, `deno@2`), or reads `devEngines.runtime` from `package.json`. |
| n/a | `token` | New: GitHub token for release lookup; defaults to `${{ github.token }}` and rarely needs to be set. |
| `bin_dest` (output) | `bin-dest` (output) | Renamed to kebab-case. New outputs `runtime-name` and `runtime-version` describe the installed runtime. |
## Inputs
### `version`
Version of pnpm to install.
**Optional** when there is a [`packageManager` field in the `package.json`](https://nodejs.org/api/corepack.html).
**Optional** when there is a [`packageManager` or `devEngines.packageManager` field in the `package.json`](https://nodejs.org/api/corepack.html).
otherwise, this field is **required** It supports npm versioning scheme, it could be an exact version (such as `10.9.8`), or a version range (such as `10`, `10.x.x`, `10.9.x`, `^10.9.8`, `*`, etc.), or `latest`.
@@ -52,13 +104,13 @@ If `run_install` is a YAML string representation of either an object or an array
### `package_json_file`
**Optional** (_type:_ `string`, _default:_ `package.json`) File path to the `package.json`/[`package.yaml`](https://github.com/pnpm/pnpm/pull/1799) to read "packageManager" configuration.
**Optional** (_type:_ `string`, _default:_ `package.json`) File path to the `package.json`/[`package.yaml`](https://github.com/pnpm/pnpm/pull/1799) to read `packageManager` or `devEngines.packageManager` configuration.
### `standalone`
**Optional** (_type:_ `boolean`, _default:_ `false`) When set to true, [@pnpm/exe](https://www.npmjs.com/package/@pnpm/exe), which is a Node.js bundled package, will be installed, enabling using `pnpm` without Node.js.
**Optional** (_type:_ `boolean`, _default:_ `false`) For pnpm v11 and earlier, install [@pnpm/exe](https://www.npmjs.com/package/@pnpm/exe), enabling pnpm to run without Node.js.
This is useful when you want to use a incompatible pair of Node.js and pnpm.
For pnpm v12, this input has no effect because the plain `pnpm` package already installs a standalone native executable.
## Outputs
@@ -74,7 +126,7 @@ Location of `pnpm` and `pnpx` command.
### Install only pnpm without `packageManager`
This works when the repo either doesn't have a `package.json` or has a `package.json` but it doesn't specify `packageManager`.
This works when the repo either doesn't have a `package.json` or has a `package.json` but it doesn't specify `packageManager` or `devEngines.packageManager`.
```yaml
on:
@@ -93,7 +145,7 @@ jobs:
### Install only pnpm with `packageManager`
Omit `version` input to use the version in the [`packageManager` field in the `package.json`](https://nodejs.org/api/corepack.html).
Omit `version` input to use the version in the [`packageManager` or `devEngines.packageManager` field in the `package.json`](https://nodejs.org/api/corepack.html).
```yaml
on:
@@ -187,7 +239,7 @@ jobs:
## Notes
This action does not setup Node.js for you, use [actions/setup-node](https://github.com/actions/setup-node) yourself.
This action does not set up Node.js. Use [actions/setup-node](https://github.com/actions/setup-node) yourself. As an alternative for pnpm v11 or newer, [`pnpm/setup`](https://github.com/pnpm/setup) can install pnpm and Node.js in a single step.
## License
+1 -1
View File
@@ -28,7 +28,7 @@ inputs:
required: false
default: 'package.json'
standalone:
description: When set to true, @pnpm/exe, which is a Node.js bundled package, will be installed, enabling using pnpm without Node.js.
description: When set to true for pnpm v11 and earlier, install @pnpm/exe to use pnpm without Node.js. pnpm v12 uses the plain pnpm package's native executable.
required: false
default: 'false'
outputs:
+156 -156
View File
File diff suppressed because one or more lines are too long
+2
View File
@@ -14,10 +14,12 @@
"@types/expand-tilde": "^2.0.2",
"@types/node": "^22.0.0",
"expand-tilde": "^2.0.2",
"semver": "^7.8.5",
"yaml": "^2.3.4",
"zod": "^3.22.4"
},
"devDependencies": {
"@types/semver": "^7.8.0",
"esbuild": "^0.27.4",
"typescript": "^5.3.3"
}
+18
View File
@@ -29,6 +29,9 @@ importers:
expand-tilde:
specifier: ^2.0.2
version: 2.0.2
semver:
specifier: ^7.8.5
version: 7.8.5
yaml:
specifier: ^2.3.4
version: 2.7.0
@@ -36,6 +39,9 @@ importers:
specifier: ^3.22.4
version: 3.24.1
devDependencies:
'@types/semver':
specifier: ^7.8.0
version: 7.8.0
esbuild:
specifier: ^0.27.4
version: 0.27.4
@@ -293,6 +299,9 @@ packages:
'@types/node@22.19.11':
resolution: {integrity: sha512-BH7YwL6rA93ReqeQS1c4bsPpcfOmJasG+Fkr6Y59q83f9M1WcBRHR2vM+P9eOisYRcN3ujQoiZY8uk5W+1WL8w==}
'@types/semver@7.8.0':
resolution: {integrity: sha512-1mAINjtQCXXeLkJ9ehXkwOcBpqtLxiVtKhpUf83DdRNdQKV0iXZpaHYqRr7nj+wvxuJzoAmAwXI+sCNMv1CzLQ==}
'@typespec/ts-http-runtime@0.3.0':
resolution: {integrity: sha512-sOx1PKSuFwnIl7z4RN0Ls7N9AQawmR9r66eI5rFCzLDIs8HTIYrIpH9QjYWoX0lkgGrkLxXhi4QnK7MizPRrIg==}
engines: {node: '>=20.0.0'}
@@ -463,6 +472,11 @@ packages:
resolution: {integrity: sha512-BR7VvDCVHO+q2xBEWskxS6DJE1qRnb7DxzUrogb71CWoSficBxYsiAGd+Kl0mmq/MprG9yArRkyrQxTO6XjMzA==}
hasBin: true
semver@7.8.5:
resolution: {integrity: sha512-Y7/KDsb8LjooZpwaqGyulO6DQlksgCncchHGk+sZIY4SBvUocMBEFH5Ur1fI4dV+Jvl0w6cjvucaIi40puRioA==}
engines: {node: '>=10'}
hasBin: true
strnum@2.1.1:
resolution: {integrity: sha512-7ZvoFTiCnGxBtDqJ//Cu6fWtZtc7Y3x+QOirG15wztbdngGSkht27o2pyGWrVy0b4WAy3jbKmnoK6g5VlVNUUw==}
@@ -770,6 +784,8 @@ snapshots:
dependencies:
undici-types: 6.21.0
'@types/semver@7.8.0': {}
'@typespec/ts-http-runtime@0.3.0':
dependencies:
http-proxy-agent: 7.0.2
@@ -957,6 +973,8 @@ snapshots:
semver@6.3.1: {}
semver@7.8.5: {}
strnum@2.1.1: {}
tr46@0.0.3: {}
+14 -14
View File
@@ -1,9 +1,5 @@
#!/usr/bin/env node
// Usage: node scripts/update-bootstrap.mjs [version]
// If version is omitted, fetches the latest next-11 tag from npm.
// Regenerates the bootstrap lockfiles used by action-setup to install pnpm via npm.
import { execSync } from 'child_process'
import { mkdtempSync, rmSync, readFileSync, writeFileSync } from 'fs'
import { join } from 'path'
@@ -11,21 +7,24 @@ import { tmpdir } from 'os'
const BOOTSTRAP_DIR = new URL('../src/install-pnpm/bootstrap/', import.meta.url).pathname
const version = process.argv[2] || resolveLatestVersion()
const legacyVersion = process.argv[2] || resolveLatestVersion(11)
const nativeVersion = process.argv[3] || resolveLatestVersion(12)
console.log(`Updating bootstrap lockfiles to pnpm@${version} ...`)
console.log(`Updating bootstrap lockfiles to pnpm@${legacyVersion} and pnpm@${nativeVersion} ...`)
generateLock('pnpm-lock.json', { pnpm: version }, 'bootstrap-pnpm')
generateLock('exe-lock.json', { '@pnpm/exe': version }, 'bootstrap-exe')
generateLock('pnpm-lock.json', { pnpm: legacyVersion }, 'bootstrap-pnpm')
generateLock('exe-lock.json', { '@pnpm/exe': legacyVersion }, 'bootstrap-exe')
generateLock('native-lock.json', { pnpm: nativeVersion }, 'bootstrap-native-pnpm')
console.log('Done!')
function resolveLatestVersion() {
const json = execSync('npm view @pnpm/exe dist-tags --json', { encoding: 'utf8' })
const tags = JSON.parse(json)
const version = tags['next-11'] || tags['latest']
function resolveLatestVersion(major) {
const json = execSync('npm view pnpm dist-tags --json', { encoding: 'utf8' })
const parsed = JSON.parse(json)
const tags = Array.isArray(parsed) ? parsed[0] : parsed
const version = tags[`next-${major}`] || tags[`latest-${major}`]
if (!version) {
console.error('Could not determine latest pnpm version from npm dist-tags')
console.error(`Could not determine latest pnpm v${major} version from npm dist-tags`)
process.exit(1)
}
return version
@@ -40,7 +39,8 @@ function generateLock(filename, dependencies, name) {
const parsed = JSON.parse(lock)
parsed.name = name
writeFileSync(join(BOOTSTRAP_DIR, filename), JSON.stringify(parsed, null, 2) + '\n')
console.log(` ${filename} -> ${Object.values(dependencies)[0]}@${version}`)
const [packageName, packageVersion] = Object.entries(dependencies)[0]
console.log(` ${filename} -> ${packageName}@${packageVersion}`)
} finally {
rmSync(tmp, { recursive: true, force: true })
}
+11 -2
View File
@@ -18,9 +18,18 @@ export async function runRestoreCache(inputs: Inputs) {
debug(`Primary key is ${primaryKey}`)
saveState('cache_primary_key', primaryKey)
let cacheKey = await restoreCache([cachePath], primaryKey)
// We don't need to download everything again if only one dependency changed
// We can still re-use previous store to cache the rest of the unchanged dependencies
const restoreKeys = [
`pnpm-cache-${process.env.RUNNER_OS}-${os.arch()}-`
];
setOutput('cache-hit', Boolean(cacheKey))
let cacheKey = await restoreCache([cachePath], primaryKey, restoreKeys)
// A restore-key (prefix) match still restores an older store, but "cache-hit"
// must only report an exact primary-key match, so dependency installation
// is not skipped when the lockfile has changed.
setOutput('cache-hit', cacheKey === primaryKey)
if (!cacheKey) {
info(`Cache is not found`)
+33 -33
View File
@@ -5,18 +5,18 @@
"packages": {
"": {
"dependencies": {
"@pnpm/exe": "11.1.1"
"@pnpm/exe": "11.25.0"
}
},
"node_modules/@pnpm/exe": {
"version": "11.1.1",
"resolved": "https://registry.npmjs.org/@pnpm/exe/-/exe-11.1.1.tgz",
"integrity": "sha512-5mQnDW1NCBRRWA+cnGhQO+tIrfSfWm3/IyGxU88LnT+tzNW5UrwwKfjsnnYJToyAjIfdfEJtJKUxCvP+mhA+nQ==",
"version": "11.25.0",
"resolved": "https://registry.npmjs.org/@pnpm/exe/-/exe-11.25.0.tgz",
"integrity": "sha512-X19R2uC+VAJ4UJQE9c/PCdOXbDaWnZtad7WUrTHBFQuMVaK9MAHbyO/WgahQCuRtTmJkLbxcWKKCk+JeTYFm/g==",
"hasInstallScript": true,
"license": "MIT",
"dependencies": {
"@reflink/reflink": "0.1.19",
"detect-libc": "^2.0.3"
"detect-libc": "^2.1.2"
},
"bin": {
"pn": "pn",
@@ -28,19 +28,19 @@
"url": "https://opencollective.com/pnpm"
},
"optionalDependencies": {
"@pnpm/linux-arm64": "11.1.1",
"@pnpm/linux-x64": "11.1.1",
"@pnpm/linuxstatic-arm64": "11.1.1",
"@pnpm/linuxstatic-x64": "11.1.1",
"@pnpm/macos-arm64": "11.1.1",
"@pnpm/win-arm64": "11.1.1",
"@pnpm/win-x64": "11.1.1"
"@pnpm/linux-arm64": "11.25.0",
"@pnpm/linux-x64": "11.25.0",
"@pnpm/linuxstatic-arm64": "11.25.0",
"@pnpm/linuxstatic-x64": "11.25.0",
"@pnpm/macos-arm64": "11.25.0",
"@pnpm/win-arm64": "11.25.0",
"@pnpm/win-x64": "11.25.0"
}
},
"node_modules/@pnpm/linux-arm64": {
"version": "11.1.1",
"resolved": "https://registry.npmjs.org/@pnpm/linux-arm64/-/linux-arm64-11.1.1.tgz",
"integrity": "sha512-u9hs51XV0/gU5LLfNLoQsozGKIxNjxsh/0xPr+8Hny0M38psa4lBtwFvarL2bLToPIrtueQYi65LdlzRxITRyg==",
"version": "11.25.0",
"resolved": "https://registry.npmjs.org/@pnpm/linux-arm64/-/linux-arm64-11.25.0.tgz",
"integrity": "sha512-ra8akqhzsbcOhKSJ9fFV8H+Oc9uGQAcp/XmIBEdT+8hPPoZCit3+RNCHmg8bLoNvpSLtRvZE0WFCMj7WyzxeBA==",
"cpu": [
"arm64"
],
@@ -54,9 +54,9 @@
}
},
"node_modules/@pnpm/linux-x64": {
"version": "11.1.1",
"resolved": "https://registry.npmjs.org/@pnpm/linux-x64/-/linux-x64-11.1.1.tgz",
"integrity": "sha512-yQO9i57oyJmIG22BjV7sqLUT2syKQohiku8yNZRgp7M6wsVkikpVLLVSpBifQnrI/P/roueKnWSUEESH1aPaoA==",
"version": "11.25.0",
"resolved": "https://registry.npmjs.org/@pnpm/linux-x64/-/linux-x64-11.25.0.tgz",
"integrity": "sha512-pQl/L10diKQCbF73viRrtVU8qVWMTudUCSG1uZ+EWBNKtU9Sbxe6Q378diXDb1uTwSgUVMQoypxlC1MTzh7qvQ==",
"cpu": [
"x64"
],
@@ -70,9 +70,9 @@
}
},
"node_modules/@pnpm/linuxstatic-arm64": {
"version": "11.1.1",
"resolved": "https://registry.npmjs.org/@pnpm/linuxstatic-arm64/-/linuxstatic-arm64-11.1.1.tgz",
"integrity": "sha512-FUZB8L9Z8L5m88G0RTx5AsHFr5yUQPW+28zQdTNUWxiLwj11FW/fOLodYdcNYHdNJFepsZyqt3aRnpiqIdZb2g==",
"version": "11.25.0",
"resolved": "https://registry.npmjs.org/@pnpm/linuxstatic-arm64/-/linuxstatic-arm64-11.25.0.tgz",
"integrity": "sha512-cYcrbB/xN1N6/5VUlFuHblb1gNyJgZv1CF5Pk1T0sHJxQMY4DFJV3OqHVAgahxyUfSTaQcVLvH1H2JFvd/+sgw==",
"cpu": [
"arm64"
],
@@ -89,9 +89,9 @@
}
},
"node_modules/@pnpm/linuxstatic-x64": {
"version": "11.1.1",
"resolved": "https://registry.npmjs.org/@pnpm/linuxstatic-x64/-/linuxstatic-x64-11.1.1.tgz",
"integrity": "sha512-I/z56hfa1zM5F/Unup/1NrgsA+dcptsKQ2TjJLFz3wHKDx0RLrfF7DB0Rkpnr5IoAZ33v0GFZjlGhkOtc9VFGw==",
"version": "11.25.0",
"resolved": "https://registry.npmjs.org/@pnpm/linuxstatic-x64/-/linuxstatic-x64-11.25.0.tgz",
"integrity": "sha512-HXDtaeQod16DDMUUcVLIMxvEc1jKn7IYsNPwbwAPs/Je/d3umRPJi3Ejjdn6e9qpXN6Oon+yvSsJr7B9oDt6KA==",
"cpu": [
"x64"
],
@@ -108,9 +108,9 @@
}
},
"node_modules/@pnpm/macos-arm64": {
"version": "11.1.1",
"resolved": "https://registry.npmjs.org/@pnpm/macos-arm64/-/macos-arm64-11.1.1.tgz",
"integrity": "sha512-YQu6fC27F4jTIpXhF+4PdzOV7uSnVVG9KUxj5W+AFj0XFlUvBw+I1NsoPCY6uV1nccxWpIAZOTZtSj8+hWPb8w==",
"version": "11.25.0",
"resolved": "https://registry.npmjs.org/@pnpm/macos-arm64/-/macos-arm64-11.25.0.tgz",
"integrity": "sha512-m/eAgEqKhiSexGxWPHNXNnSRI0hudymg6K7LbrU2EoDs9IgJ28OKEz9mGxMzhkYBweEquR4k5teMNes/aToy9w==",
"cpu": [
"arm64"
],
@@ -124,9 +124,9 @@
}
},
"node_modules/@pnpm/win-arm64": {
"version": "11.1.1",
"resolved": "https://registry.npmjs.org/@pnpm/win-arm64/-/win-arm64-11.1.1.tgz",
"integrity": "sha512-2HvZut3IcKPxzIfOjBJ4677PaLIh57mWccL86O+q71QhO5emnQvht0CE19IoEyUIOEe1WjlN+Su/dD5k6CuGyg==",
"version": "11.25.0",
"resolved": "https://registry.npmjs.org/@pnpm/win-arm64/-/win-arm64-11.25.0.tgz",
"integrity": "sha512-oAeECbtZ+eJziaBmPUkwJM8Dx7KVQ5FO367AXTjD2HGfB5ob1Bcu5hoUF5RBTgDBiP9fRQ1u13uAEpqar/6NLA==",
"cpu": [
"arm64"
],
@@ -140,9 +140,9 @@
}
},
"node_modules/@pnpm/win-x64": {
"version": "11.1.1",
"resolved": "https://registry.npmjs.org/@pnpm/win-x64/-/win-x64-11.1.1.tgz",
"integrity": "sha512-QXBIBErgPhGLovOVzTRIpHsejFKebyqlcF3fea/TfH87gkhN5yWH0WuTPRBoOWvpk6aNhjDW4RPUMx8RaPqxjw==",
"version": "11.25.0",
"resolved": "https://registry.npmjs.org/@pnpm/win-x64/-/win-x64-11.25.0.tgz",
"integrity": "sha512-8/n+wCc0a8TRYTMFqti93Vh0cscdJ25xfMyYSDdXrLUh2ccxSFuS+SE7cNPjd/nOXoFAJvdW0kwfbyRPLa16/w==",
"cpu": [
"x64"
],
+154
View File
@@ -0,0 +1,154 @@
{
"name": "bootstrap-native-pnpm",
"lockfileVersion": 3,
"requires": true,
"packages": {
"": {
"dependencies": {
"pnpm": "12.3.4"
}
},
"node_modules/@pnpm/exe.darwin-arm64": {
"version": "12.3.4",
"resolved": "https://registry.npmjs.org/@pnpm/exe.darwin-arm64/-/exe.darwin-arm64-12.3.4.tgz",
"integrity": "sha512-PAyUol8T1+/+ViOiXAt51ECA+QnfXCqz6foL4bW+LsoX0NcVd5XVEM2mRQu+LV4oc7uRz9zf9U0P+XFfuQeDAw==",
"cpu": [
"arm64"
],
"license": "MIT",
"optional": true,
"os": [
"darwin"
]
},
"node_modules/@pnpm/exe.darwin-x64": {
"version": "12.3.4",
"resolved": "https://registry.npmjs.org/@pnpm/exe.darwin-x64/-/exe.darwin-x64-12.3.4.tgz",
"integrity": "sha512-fxP9JCk0Cdye+ePuj+GJJLMUMTqHGWRdb1dtv4How876uQ2ehxvenpgiYAir/ceO9PsYUZkFTtyZdx+rRu5QOA==",
"cpu": [
"x64"
],
"license": "MIT",
"optional": true,
"os": [
"darwin"
]
},
"node_modules/@pnpm/exe.linux-arm64": {
"version": "12.3.4",
"resolved": "https://registry.npmjs.org/@pnpm/exe.linux-arm64/-/exe.linux-arm64-12.3.4.tgz",
"integrity": "sha512-t71AVA7LRqiKTyZ5xMYaZc2n5DfdpMbfokZuiIOXHBOM03ECnF0t4iYwaBDqJgVjlKYUOwaF/bRQajGNA4cJ4w==",
"cpu": [
"arm64"
],
"libc": [
"glibc"
],
"license": "MIT",
"optional": true,
"os": [
"linux"
]
},
"node_modules/@pnpm/exe.linux-arm64-musl": {
"version": "12.3.4",
"resolved": "https://registry.npmjs.org/@pnpm/exe.linux-arm64-musl/-/exe.linux-arm64-musl-12.3.4.tgz",
"integrity": "sha512-FBOt0/7ye6O6q4AllVV5QMviB6qE6fqkeczV/+MDWQsmo+QJrlfsh6X7CpH/tClVpBZEyIbjpUoT8bNhCYBxEg==",
"cpu": [
"arm64"
],
"libc": [
"musl"
],
"license": "MIT",
"optional": true,
"os": [
"linux"
]
},
"node_modules/@pnpm/exe.linux-x64": {
"version": "12.3.4",
"resolved": "https://registry.npmjs.org/@pnpm/exe.linux-x64/-/exe.linux-x64-12.3.4.tgz",
"integrity": "sha512-2ZqOlSPkfwX1h5cR+FPiWf8+F+2hZT/3TvhUK5sigHqwaQCIiq8R7CGxhndKs63JtcLi2a1Qpo+wX/EoyfjyJQ==",
"cpu": [
"x64"
],
"libc": [
"glibc"
],
"license": "MIT",
"optional": true,
"os": [
"linux"
]
},
"node_modules/@pnpm/exe.linux-x64-musl": {
"version": "12.3.4",
"resolved": "https://registry.npmjs.org/@pnpm/exe.linux-x64-musl/-/exe.linux-x64-musl-12.3.4.tgz",
"integrity": "sha512-RPmk7Jb/aYaFvL2iyDN/AtMY+hUEsue732WmXpcuQ9tBpMnGyA5py7Z3+e+qmQaJ0zY/4ni9jJiyPBQHujmv6w==",
"cpu": [
"x64"
],
"libc": [
"musl"
],
"license": "MIT",
"optional": true,
"os": [
"linux"
]
},
"node_modules/@pnpm/exe.win32-arm64": {
"version": "12.3.4",
"resolved": "https://registry.npmjs.org/@pnpm/exe.win32-arm64/-/exe.win32-arm64-12.3.4.tgz",
"integrity": "sha512-ANyrHqyqco6SXBysUTRF74itDyyraea7IbFsKFdNXTjcFnfycTDx37EwuhdpPYFNSIh2JhUG4fByclsRfiHX7w==",
"cpu": [
"arm64"
],
"license": "MIT",
"optional": true,
"os": [
"win32"
]
},
"node_modules/@pnpm/exe.win32-x64": {
"version": "12.3.4",
"resolved": "https://registry.npmjs.org/@pnpm/exe.win32-x64/-/exe.win32-x64-12.3.4.tgz",
"integrity": "sha512-WH/KqBPY/hq2Tb7SgQltEZytimcjgKRaCRL/aM9CI0c67iKc5TVmHUhIiL3Ux9FB4bWn36i6XewUcScQI+zG8w==",
"cpu": [
"x64"
],
"license": "MIT",
"optional": true,
"os": [
"win32"
]
},
"node_modules/pnpm": {
"version": "12.3.4",
"resolved": "https://registry.npmjs.org/pnpm/-/pnpm-12.3.4.tgz",
"integrity": "sha512-lhqkH7B32joEpEHZ+OFevAyW2o73ELLrZ7+e58sGEOq9SPH9hfUc/+c4RnhfoPh8VqOocqHYk/hEZ0G1zORUVw==",
"hasInstallScript": true,
"license": "MIT",
"bin": {
"pn": "pn",
"pnpm": "pnpm",
"pnpx": "pnpx",
"pnx": "pnx"
},
"engines": {
"node": ">=18.*"
},
"optionalDependencies": {
"@pnpm/exe.darwin-arm64": "12.3.4",
"@pnpm/exe.darwin-x64": "12.3.4",
"@pnpm/exe.linux-arm64": "12.3.4",
"@pnpm/exe.linux-arm64-musl": "12.3.4",
"@pnpm/exe.linux-x64": "12.3.4",
"@pnpm/exe.linux-x64-musl": "12.3.4",
"@pnpm/exe.win32-arm64": "12.3.4",
"@pnpm/exe.win32-x64": "12.3.4"
}
}
}
}
+4 -4
View File
@@ -5,13 +5,13 @@
"packages": {
"": {
"dependencies": {
"pnpm": "11.1.1"
"pnpm": "11.25.0"
}
},
"node_modules/pnpm": {
"version": "11.1.1",
"resolved": "https://registry.npmjs.org/pnpm/-/pnpm-11.1.1.tgz",
"integrity": "sha512-0f319zxhe2T6GlaoHDyN/g6WbjOmAQqiVrUXrne+Idk+Ba/8DeGoOw5PKdVp9otEaujwaM1yR8C7PfD7TXvfmg==",
"version": "11.25.0",
"resolved": "https://registry.npmjs.org/pnpm/-/pnpm-11.25.0.tgz",
"integrity": "sha512-XN6SW08HX3Jetx+64YpC/+eEUkeJ8ZthxzHLhyHsKKruFg4BqNWvT+2ypCzb8wDv4j2zVrDUoXtNY+EfirfJVg==",
"license": "MIT",
"bin": {
"pn": "bin/pnpm.mjs",
+51 -23
View File
@@ -6,11 +6,28 @@ import path from 'path'
import util from 'util'
import { Inputs } from '../inputs'
import { parse as parseYaml } from 'yaml'
import { satisfies, subset, validRange } from 'semver'
import pnpmLock from './bootstrap/pnpm-lock.json'
import exeLock from './bootstrap/exe-lock.json'
import nativeLock from './bootstrap/native-lock.json'
const BOOTSTRAP_PNPM_PACKAGE_JSON = JSON.stringify({ private: true, dependencies: { pnpm: pnpmLock.packages['node_modules/pnpm'].version } })
const BOOTSTRAP_EXE_PACKAGE_JSON = JSON.stringify({ private: true, dependencies: { '@pnpm/exe': exeLock.packages['node_modules/@pnpm/exe'].version } })
const bootstrapPnpmVersion = pnpmLock.packages['node_modules/pnpm'].version
const bootstrapExeVersion = exeLock.packages['node_modules/@pnpm/exe'].version
const bootstrapNativeVersion = nativeLock.packages['node_modules/pnpm'].version
const BOOTSTRAP_PNPM_PACKAGE_JSON = JSON.stringify({
private: true,
dependencies: { pnpm: bootstrapPnpmVersion },
})
const BOOTSTRAP_EXE_PACKAGE_JSON = JSON.stringify({
private: true,
dependencies: { '@pnpm/exe': bootstrapExeVersion },
allowScripts: { [`@pnpm/exe@${bootstrapExeVersion}`]: true },
})
const BOOTSTRAP_NATIVE_PACKAGE_JSON = JSON.stringify({
private: true,
dependencies: { pnpm: bootstrapNativeVersion },
allowScripts: { [`pnpm@${bootstrapNativeVersion}`]: true },
})
export interface SelfInstallerResult {
exitCode: number
@@ -19,18 +36,20 @@ export interface SelfInstallerResult {
export async function runSelfInstaller(inputs: Inputs): Promise<SelfInstallerResult> {
const { version, dest, packageJsonFile } = inputs
// pnpm v11 requires Node >= 22.13; use standalone (exe) bootstrap which
// bundles its own Node.js when the system Node is too old
const systemNode = await getSystemNodeVersion()
const standalone = inputs.standalone || systemNode.major < 22 || (systemNode.major === 22 && systemNode.minor < 13)
const targetVersion = readTargetVersion({ version, packageJsonFile })
const native = targetsPnpm12(targetVersion)
let standalone = false
if (!native) {
const systemNode = await getSystemNodeVersion()
standalone = inputs.standalone || systemNode.major < 22 || (systemNode.major === 22 && systemNode.minor < 13)
}
// Install bootstrap pnpm via npm (integrity verified by committed lockfile)
await rm(dest, { recursive: true, force: true })
await mkdir(dest, { recursive: true })
const lockfile = standalone ? exeLock : pnpmLock
const packageJson = standalone ? BOOTSTRAP_EXE_PACKAGE_JSON : BOOTSTRAP_PNPM_PACKAGE_JSON
const lockfile = native ? nativeLock : standalone ? exeLock : pnpmLock
const packageJson = native ? BOOTSTRAP_NATIVE_PACKAGE_JSON : standalone ? BOOTSTRAP_EXE_PACKAGE_JSON : BOOTSTRAP_PNPM_PACKAGE_JSON
await writeFile(path.join(dest, 'package.json'), packageJson)
await writeFile(path.join(dest, 'package-lock.json'), JSON.stringify(lockfile))
@@ -53,9 +72,6 @@ export async function runSelfInstaller(inputs: Inputs): Promise<SelfInstallerRes
return { exitCode: npmExitCode, binDest: path.join(dest, 'node_modules', '.bin') }
}
// On Windows with standalone mode, npm's .bin shims can't properly
// execute the extensionless @pnpm/exe native binaries. Add the
// @pnpm/exe directory directly to PATH so pnpm.exe is found natively.
const pnpmHome = standalone && process.platform === 'win32'
? path.join(dest, 'node_modules', '@pnpm', 'exe')
: path.join(dest, 'node_modules', '.bin')
@@ -73,22 +89,28 @@ export async function runSelfInstaller(inputs: Inputs): Promise<SelfInstallerRes
const pnpmBinLink = path.join(dest, 'node_modules', '.bin', 'pnpm')
if (!existsSync(pnpmBinLink)) {
await mkdir(path.join(dest, 'node_modules', '.bin'), { recursive: true })
const target = standalone
? path.join('..', '@pnpm', 'exe', 'pnpm')
: path.join('..', 'pnpm', 'bin', 'pnpm.mjs')
const target = native
? path.join('..', 'pnpm', 'pnpm')
: standalone
? path.join('..', '@pnpm', 'exe', 'pnpm')
: path.join('..', 'pnpm', 'bin', 'pnpm.mjs')
await symlink(target, pnpmBinLink)
}
}
const bootstrapPnpm = standalone
? path.join(dest, 'node_modules', '@pnpm', 'exe', process.platform === 'win32' ? 'pnpm.exe' : 'pnpm')
: path.join(dest, 'node_modules', 'pnpm', 'bin', 'pnpm.mjs')
const bootstrapPnpm = native
? path.join(dest, 'node_modules', 'pnpm', process.platform === 'win32' ? 'pnpm.exe' : 'pnpm')
: standalone
? path.join(dest, 'node_modules', '@pnpm', 'exe', process.platform === 'win32' ? 'pnpm.exe' : 'pnpm')
: path.join(dest, 'node_modules', 'pnpm', 'bin', 'pnpm.mjs')
const bootstrapVersion = native ? bootstrapNativeVersion : standalone ? bootstrapExeVersion : bootstrapPnpmVersion
// Self-update the bootstrap to the requested pnpm version. readTargetVersion
// either returns a value or throws, so this always runs.
const targetVersion = readTargetVersion({ version, packageJsonFile })
const cmd = standalone ? bootstrapPnpm : process.execPath
const args = standalone ? ['self-update', targetVersion] : [bootstrapPnpm, 'self-update', targetVersion]
if (targetVersion === bootstrapVersion || (native && satisfies(bootstrapVersion, targetVersion))) {
return { exitCode: 0, binDest: pnpmHome }
}
const cmd = native || standalone ? bootstrapPnpm : process.execPath
const args = native || standalone ? ['self-update', targetVersion] : [bootstrapPnpm, 'self-update', targetVersion]
const exitCode = await runCommand(cmd, args, { cwd: dest })
if (exitCode !== 0) {
return { exitCode, binDest: pnpmHome }
@@ -179,6 +201,12 @@ Please specify it by one of the following ways:
- in the package.json with the key "devEngines.packageManager"`)
}
function targetsPnpm12(version: string): boolean {
if (version === 'latest-12' || version === 'next-12') return true
const range = validRange(version)
return range !== null && subset(range, '>=12.0.0 <13.0.0')
}
function getSystemNodeVersion(): Promise<{ major: number; minor: number }> {
return new Promise((resolve) => {
const cp = spawn('node', ['--version'], { stdio: ['pipe', 'pipe', 'pipe'], shell: process.platform === 'win32' })