Commit Graph
4 Commits
Author SHA1 Message Date
Luan TaraschiandZoltan Kochan 5610fefa38 fix(git-resolver): resolve ssh git URLs that carry no user info (#13726)
## Summary

SSH Git dependencies without user information could crash during parsing because the TypeScript resolver expected every authority to contain `user@host`. Bracketed IPv6 addresses exposed a second issue: colons inside the address were mistaken for an SCP-style separator.

This change keeps the TypeScript and Rust implementations aligned:

- the host lookup falls back to the full authority when no user information is present;
- only the part after a bracketed host is inspected for an SCP separator or port;
- the Rust rewrite finds the final separator directly with `rfind(':')`, which expresses the intended operation without allocating a temporary vector;
- regression coverage includes no-user-info URLs, bracketed IPv6 hosts, ports, SCP-style paths, and path extraction.

---------

Co-authored-by: Zoltan Kochan <z@kochan.io>
2026-08-12 01:21:02 +02:00
Minha KangandZoltan Kochan de1c7be5fa fix(git-resolver): make the ls-remote prompt guard reach git (#13523)
#13471 passed GIT_TERMINAL_PROMPT=0 in the options given to
graceful-git, but graceful-git forwards only `cwd` to the process it
spawns, so the override never reached git: a repository that needs
credentials still made git prompt on the terminal, and `pnpm outdated`
with a private GitHub Actions repo (as well as resolving a private git
dependency) still hung.

Spawn git through safe-execa directly with the guard in the child
environment, keeping the single-retry policy of the ref-read call site.
The regression went unnoticed because the test mocked graceful-git and
asserted that the env option was handed to it, not that it reached git;
the mocks now sit on the process-spawn boundary and every invocation is
checked, so dropping the guard fails 25 tests.

The Rust runner sets the variable on the Command itself and was already
correct.

Fixes pnpm/pnpm#13522

---------

Co-authored-by: Zoltan Kochan <z@kochan.io>
2026-08-07 11:34:31 +02:00
Zoltan KochanandClaude Fable 5 d2ed60afba test: make git-resolver and dlx git tests immune to GitHub flakiness (#12885)
The git-resolver unit tests hit live github.com by default: the mocks for
fetchWithDispatcher and graceful-git existed, but beforeEach restored the
real implementations. When GitHub throttles the shared CI runner IPs, the
HEAD probe in isRepoPublic() fails (it has zero retries and treats any
error as "private"), and resolution silently degrades from the hosted
tarball to a git clone, changing the resolved id and failing the
assertions. This broke the main branch build at
https://github.com/pnpm/pnpm/actions/runs/29026897310/job/86153736091

The mocks are now the default: fetch reports every repository as public
and graceful-git serves ls-remote output from a fixture table captured
from the real repositories, with the same commit hashes the assertions
already expected. The private-repo-over-HTTPS test now calls
mockFetchAsPrivate() explicitly instead of relying on a real 404 for the
nonexistent github.com/foo/bar. The one live-network case in
parsePref.test.ts got the same treatment. The suite drops from ~40s to
under half a second and runs offline.

The dlx e2e test stays a genuine end-to-end test against GitHub, but its
allowBuild list now approves both resolution shapes of the same commit
(codeload tarball and git+https clone), so the resolver's
rate-limit-induced fallback no longer trips the
GIT_DEP_PREPARE_NOT_ALLOWED gate, as seen in
https://github.com/pnpm/pnpm/actions/runs/29029971938/job/86170695840

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-10 00:53:03 +02:00
Zoltan Kochan fc2f33912e refactor: move the TypeScript pnpm CLI into a pnpm11/ directory (#12537)
The TypeScript pnpm CLI freezes at v11; pnpm 12 will be the Rust pacquet
port. To make that split legible, all TypeScript source, test, and build
directories move under a new top-level pnpm11/ directory. The name states
the version boundary rather than implying a behavioral fork, since the two
stacks are meant to behave identically.

Scope is source-only: the shared workspace root stays at the repo root.
pnpm-workspace.yaml, package.json, pnpm-lock.yaml, .pnpmfile.cjs,
.meta-updater, __patches__, .changeset, .husky, and the lint/spell configs
remain in place, so one pnpm workspace and one Cargo workspace still span
all three products. pnpr/client and pacquet/tasks/registry-mock stay as
cross-product workspace members.

Rewiring the move required:
- pnpm-workspace.yaml globs prefixed with pnpm11/
- root package.json script paths, eslint.config.mjs, tsconfig.lint.json,
  .gitignore, and CODEOWNERS updated
- .meta-updater/src/index.ts literals repointed (pnpm11/pnpm/package.json,
  pnpm11/__utils__, pnpm11/__typings__, and the main package directory)
- regenerated every moved package's repository/homepage URL via meta-updater
- pnpm11/pnpm/bundle-deps.ts and __utils__/scripts/src/typecheck-only.ts
  climb one more level to reach the repo root

.meta-updater stays at the repo root because @pnpm/meta-updater resolves
its config at <cwd>/.meta-updater/main.mjs.

TS CI (.github/workflows/ci.yml) now only runs when pnpm11/-relevant paths
change, via a dorny/paths-filter changes job plus a TS CI / Success
aggregate gate; branch protection should require only that gate.
2026-06-20 14:36:25 +02:00