* chore(release): 11.28.0, pacquet 12.7.0, pnpr 0.1.0-alpha.13
* docs(release): curate the 11.28.0 and 12.7.0 release pages
Group both pages under subject headings with a lead paragraph that
names the headline changes and the security fixes, and move the
security entries to the top of the patch section.
Merge entries that describe one change: the node shim version files,
ranged selectors without a package.json, SemVer build metadata,
completion injection, custom modulesDir command lookup,
list --only-projects, store status, npm_execpath, catalog and npm-alias
workspace edges, the macOS CA fallback, and the prepare/devPreinstall
skips.
Drop entries that describe no change a published version could show:
the test-only --no-optional entry on both pages, the exported
CreateNewStoreControllerOptions type, the publish availability-probe
fix for a flag first shipping in 12.7.0, and the executable-bit check
the Rust CLI never had wrong.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* docs(release): describe the bin shim part of the modulesDir entry accurately
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Initialize committed Git submodules after checkout, with the same noninteractive protocol safeguards used for Git dependency fetches. Closespnpm/pnpm#1470.
---------
Co-authored-by: Zoltan Kochan <z@kochan.io>
The default reporter repaints the terminal over anything git or ssh
prints, so when a git dependency's SSH remote needs a key passphrase or
a host key confirmation the prompt is invisible and `pnpm install` looks
hung. `GIT_TERMINAL_PROMPT=0` already made git's own credential prompts
fail fast; ssh prompts on the terminal directly, so it needs
`BatchMode=yes` through `GIT_SSH_COMMAND` to fail the same way.
Both the git resolver's `ls-remote` and every git invocation of the git
fetcher now go through one helper, `nonInteractiveGitEnv` in
`@pnpm/network.git-utils` and `disable_git_prompts` in
`pnpm-git-utils`, that sets both variables. The ssh override is skipped
when the user already selected the ssh command through
`GIT_SSH_COMMAND`, `GIT_SSH`, or the `core.sshCommand` git setting, so
a custom key or a plink setup keeps working, and setting
`GIT_SSH_COMMAND=ssh` opts back into prompting.
Closespnpm/pnpm#2227
Allow publishing from a detached HEAD when the resolved CI setting is enabled.
Run the clean-working-tree check first. Branch selection and upstream-history
checks apply when HEAD is attached to a branch; outside CI, a detached HEAD
continues to fail with ERR_PNPM_GIT_UNKNOWN_BRANCH. Verify detached HEADs with
Git before allowing the CI exception; failed lookups do not establish detachment.
Keep refused Rust Git metadata fail-closed.
Reuse the existing CI configuration in both CLI implementations. This supports
workspace release tags without assuming that a tag matches one package's version.
Closespnpm/pnpm#5894.
Remove the legacy repository changelog files now that release changelog storage defaults to the registry. The publish path composes and injects CHANGELOG.md into release tarballs, so keeping historical copies in source control duplicates generated release data.
Update adm-zip to the patched 0.6 release and override vulnerable transitive versions after the dependency audit began rejecting versions below 0.6.0.
The TypeScript pnpm CLI freezes at v11; pnpm 12 will be the Rust pacquet
port. To make that split legible, all TypeScript source, test, and build
directories move under a new top-level pnpm11/ directory. The name states
the version boundary rather than implying a behavioral fork, since the two
stacks are meant to behave identically.
Scope is source-only: the shared workspace root stays at the repo root.
pnpm-workspace.yaml, package.json, pnpm-lock.yaml, .pnpmfile.cjs,
.meta-updater, __patches__, .changeset, .husky, and the lint/spell configs
remain in place, so one pnpm workspace and one Cargo workspace still span
all three products. pnpr/client and pacquet/tasks/registry-mock stay as
cross-product workspace members.
Rewiring the move required:
- pnpm-workspace.yaml globs prefixed with pnpm11/
- root package.json script paths, eslint.config.mjs, tsconfig.lint.json,
.gitignore, and CODEOWNERS updated
- .meta-updater/src/index.ts literals repointed (pnpm11/pnpm/package.json,
pnpm11/__utils__, pnpm11/__typings__, and the main package directory)
- regenerated every moved package's repository/homepage URL via meta-updater
- pnpm11/pnpm/bundle-deps.ts and __utils__/scripts/src/typecheck-only.ts
climb one more level to reach the repo root
.meta-updater stays at the repo root because @pnpm/meta-updater resolves
its config at <cwd>/.meta-updater/main.mjs.
TS CI (.github/workflows/ci.yml) now only runs when pnpm11/-relevant paths
change, via a dorny/paths-filter changes job plus a TS CI / Success
aggregate gate; branch protection should require only that gate.