A runtime installed through devEngines.runtime with onFail: "download" is
a lockfile entry whose resolution type is `variations`. The store package
finder only knew `directory`, tarball and `git` resolutions, so the
license scanner raised ERR_PNPM_UNSUPPORTED_PACKAGE_TYPE for it.
Skipping the entry by its dep path let a crafted lockfile hide an
arbitrary subtree from the report, and the runtime does carry a license
worth reporting. `@pnpm/store.pkg-finder` now selects the variant for the
host platform (or the configured supportedArchitectures) and looks its
files up under the same store index key the installer writes, so the
scanner reads the runtime's manifest and LICENSE file like any other
package. The scanner threads supportedArchitectures through to the
finder for that selection.
pacquet already resolved the runtime's slot directory and reported the
same license, so the Rust side is unchanged and the changeset targets
only the TypeScript packages.
Fixes https://github.com/pnpm/pnpm/issues/14172
---------
Co-authored-by: Zoltan Kochan <z@kochan.io>