Merging git branch lockfiles unions their keys, so a dependency that the main branch removed after a branch lockfile was written comes back in the merged result. Resolution normally prunes it again, but --frozen-lockfile skips resolution and fails the manifest check with ERR_PNPM_OUTDATED_LOCKFILE. Once the branch lockfiles are merged, prune each importer back to what its manifest declares. The declared names are derived per dependency group the way satisfiesPackageManifest derives them, so a dependency that moved between groups is reconciled rather than left in both. Only a peer that no other field declares is auto-installed, so a dependency listed in both devDependencies and peerDependencies keeps the field that declares it rather than being dropped from it. Pruning importer edges can strand packages, so the merged lockfile then goes through pruneSharedLockfile. The Rust CLI merges branch lockfiles the same way and had the same bug. It gets the same reconciliation, hooked into the install pipeline because the lazily loaded wanted lockfile has no access to the project manifests at load time. Fixes pnpm/pnpm#13966. --------- Co-authored-by: Zoltan Kochan <z@kochan.io>
47 lines
749 B
JSON
47 lines
749 B
JSON
{
|
|
"extends": "@pnpm/tsconfig",
|
|
"compilerOptions": {
|
|
"outDir": "lib",
|
|
"rootDir": "src"
|
|
},
|
|
"include": [
|
|
"src/**/*.ts",
|
|
"../../__typings__/**/*.d.ts"
|
|
],
|
|
"references": [
|
|
{
|
|
"path": "../../core/constants"
|
|
},
|
|
{
|
|
"path": "../../core/core-loggers"
|
|
},
|
|
{
|
|
"path": "../../core/error"
|
|
},
|
|
{
|
|
"path": "../../core/logger"
|
|
},
|
|
{
|
|
"path": "../../core/types"
|
|
},
|
|
{
|
|
"path": "../../lockfile/fs"
|
|
},
|
|
{
|
|
"path": "../../lockfile/pruner"
|
|
},
|
|
{
|
|
"path": "../../resolving/resolver-base"
|
|
},
|
|
{
|
|
"path": "../../store/controller"
|
|
},
|
|
{
|
|
"path": "../modules-yaml"
|
|
},
|
|
{
|
|
"path": "../read-projects-context"
|
|
}
|
|
]
|
|
}
|