A resolve request carried the client's `minimumReleaseAge` and `trustPolicy` but not its `resolutionMode`, and `intern_config` never set `config.resolution_mode`, so every pnpr-delegated resolve ran on the server's `highest` default. A project configured for `time-based` or `lowest-direct` got a lockfile pinning the highest satisfying version of everything, with nothing to show that the setting had been dropped. The mode now travels with the request and reaches the interned config, which is what `PickPolicy::from_config` reads on the server side. It also joins both cache keys — the interned-config key and the resolution cache key — so two modes can neither share a config nor replay each other's resolution. `VerifyLockfileOptions` deliberately does not carry it: verification judges an existing lockfile against the client's policy and picks no version.
@pnpm/pnpr.client
Client library for the pnpr server. Resolves a project's dependencies server-side and returns the resolved lockfile.
How it works
- Sends
POST /v1/installto the pnpr server with the project's dependencies (and the existing lockfile, if any, for incremental resolution). - The server resolves against the client's registries, verifies the input lockfile under the client's policy, and answers with one gzipped JSON object carrying the resolved lockfile and stats.
- Returns the resolved lockfile for use with pnpm's headless install, which fetches every tarball directly from the registries in parallel — like a normal install. See pnpm/pnpm#12230.
pnpr is a stateless resolver: it stores no tarballs and serves no file content.
Usage
This package is used internally by pnpm when the pnprServer config option is set. It is not intended to be called directly, but can be used programmatically:
import { fetchFromPnpmRegistry } from '@pnpm/pnpr.client'
const { lockfile, stats } = await fetchFromPnpmRegistry({
registryUrl: 'http://localhost:4000',
dependencies: { react: '^19.0.0' },
devDependencies: { typescript: '^5.0.0' },
})
console.log(`Resolved ${stats.totalPackages} packages`)
// lockfile is ready for headless install
Configuration
Add to pnpm-workspace.yaml to enable automatically during pnpm install:
pnprServer: http://localhost:4000