Two flaws let a transient probe failure record an SSH URL for a spec that never asked for SSH: the visibility HEAD probe ran once with retries disabled and treated any failure as private, and the SSH ls-remote probe ran before the anonymous HTTPS one. On a machine with SSH keys, a throttled HEAD request resolved a public repo to git@host:..., breaking later installs on keyless CI runners with Permission denied (publickey). The resolver now retries transient HEAD failures, probes anonymous HTTPS git access before SSH for every representation except explicit SSH URLs, falls back to HTTPS when every probe fails, and records the host-archive tarball only for repos proven public - otherwise the resolution stays type: git so ambient credentials apply. TypeScript CLI only: pacquet resolves this bug class structurally via the v12 identity redesign (pnpm/pnpm#13684), which supersedes the Rust-side commits this PR previously carried. Closes pnpm/pnpm#13276. Co-authored-by: Zoltan Kochan <z@kochan.io> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
1.5 KiB
1.5 KiB
@pnpm/resolving.git-resolver, pnpm
| @pnpm/resolving.git-resolver | pnpm |
|---|---|
| patch | patch |
Fixed a CI regression where github:owner/repo dependencies (and other shorthand Git specifiers) would fail to install with Permission denied (publickey) on CI runners that lack SSH keys. The Git resolver no longer records an SSH URL unless the user explicitly wrote one (e.g. git+ssh:// or git@host:...):
- The repository visibility probe (an HTTP HEAD request) now retries transient failures such as
429 Too Many Requests, so host throttling of CI runners is no longer mistaken for a private repository. - For non-SSH specifiers, anonymous HTTPS
git ls-remoteaccess is now tried before SSH, so a public repository whose visibility probe fails still resolves to a portable HTTPS URL instead of an SSH URL that only works where SSH keys are configured. - When every probe fails, the resolver falls back to HTTPS for shorthand and HTTPS-style specifiers, and only guesses SSH when the user explicitly provided an SSH URL.
- A repository that could not be confirmed public is no longer resolved to the host's anonymous archive URL (e.g.
codeload.github.com, which would fail to download for a private repository); it stays a regulargitresolution so installs can use ambient Git credentials such as credential helpers and tokens.
Note that a private repository that is reachable both over authenticated HTTPS and over SSH now resolves to its HTTPS URL, where previous versions recorded the SSH URL.
Fixes pnpm/pnpm#13276.