A hosted git specifier that resolved over HTTPS without the repository being provably public lost its committish from the specifier written back to the manifest: `pnpm add owner/repo#develop` recorded `git+https://github.com/owner/repo.git`. The URL that branch records doubles as the `git ls-remote` target, which must carry no committish, so it was built with `noCommittish`. The committish still reached resolveRef, so the install pinned the right commit and nothing looked wrong — until the next re-resolve read a specifier that no longer named a branch and moved the dependency to the default branch. Keep the `ls-remote` target committish-free and build the recorded specifier from the same host template with the committish left in, which is what every other branch of fromHostedGit already produced through shortcut(). pacquet reaches its equivalent branch only for a URL carrying its own credentials, and drops the committish there the same way; it is fixed alongside. Fixes pnpm/pnpm#13999 --------- Co-authored-by: Zoltan Kochan <z@kochan.io>
@pnpm/resolving.git-resolver
Resolver for git-hosted packages
Installation
pnpm add @pnpm/resolving.git-resolver
Usage
'use strict'
const createResolveFromNpm = require('@pnpm/resolving.git-resolver').default
const resolveFromNpm = createResolveFromNpm({})
resolveFromNpm({
bareSpecifier: 'kevva/is-negative#16fd36fe96106175d02d066171c44e2ff83bc055'
})
.then(resolveResult => console.log(JSON.stringify(resolveResult, null, 2)))
//> {
// "id": "github.com/kevva/is-negative/16fd36fe96106175d02d066171c44e2ff83bc055",
// "normalizedBareSpecifier": "github:kevva/is-negative#16fd36fe96106175d02d066171c44e2ff83bc055",
// "resolution": {
// "tarball": "https://codeload.github.com/kevva/is-negative/tar.gz/16fd36fe96106175d02d066171c44e2ff83bc055"
// },
// "resolvedVia": "git-repository"
// }
License
MIT