The npm resolver returns the manifest object its metadata cache holds, so every
dependency that resolves to the same package version gets the same object.
Resolving a dependency then writes to it: `dependencies` is defaulted, the
read-package hook rewrites dependency fields, a deprecation notice is carried
over from the lockfile, and an `engines.runtime` entry becomes a dependency.
Copy the dependency and peer fields first, down to each peerDependenciesMeta
entry, so one install cannot decide what the next one resolves.
The copy is deliberately shallow and limited to the fields those writes reach.
Deep-cloning the manifest in the resolver instead costs ~37us per manifest
against ~0.1us here, on a path that runs once per resolved dependency edge.
Related to pnpm/pnpm#13988. That issue's exact symptom could not be
reproduced, so this is not claimed as its fix.
---------
Co-authored-by: Zoltan Kochan <z@kochan.io>