Files
pnpm/.github/workflows/update-lockfile.yml
T
Zoltan KochanandClaude Opus 5 822f2dcb23 chore(ci): install every crate through pnpm (#14824)
Commit the pnpm-managed Cargo source block. The block is a function of
Cargo.lock, so an install regenerates it byte for byte and the tracked
`.cargo/config.toml` stops reporting as modified after every install. A new
Rust CI step fails if the committed block and the lockfile drift apart.

Cargo now resolves every crate through `.pnpm/crates` and falls back to its
own registry nowhere, so each job that runs cargo needs an install behind it.
Eight did not have one: both cargo-unused jobs, the micro-benchmark, the
integrated benchmark's build and executor jobs, and the three release builds.
The new `install-crates` action gives them one and narrows the JavaScript half
with `--filter pacquet`, which a filter does not do to the Cargo half.

The release builds go through `cross`, which mounts the checkout at
`/project`. pnpm links each crate into `.pnpm/crates` with a relative symlink,
so a store outside the checkout stops resolving under that mount. Those jobs
install into a store inside the checkout instead, on Linux, the one host where
cross containerizes the build at all.

The two workflows that commit no longer discard the block. It is tracked
content now, and a run that changes it should carry the change.


Claude-Session: https://claude.ai/code/session_01Gg6uVUzLw1MniCLC81TQjP
Claude-Session: https://claude.ai/code/session_01HwJS1pAz9HHQpJWEJAiaUu

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-11 02:27:47 +02:00

80 lines
3.3 KiB
YAML

name: Update Lockfile
on:
schedule:
- cron: '0 6 * * *' # Daily at 6 AM UTC
workflow_dispatch: {} # Allow manual triggering
permissions:
contents: write
pull-requests: write
# Serialize runs so a manual dispatch and the daily schedule can't reset and
# force-push the chore/update-lockfile branch at the same time.
concurrency:
group: update-lockfile
cancel-in-progress: false
jobs:
update-lockfile:
if: github.repository == 'pnpm/pnpm' # Only run on the main repository, not forks
runs-on: blacksmith-4vcpu-ubuntu-2404
timeout-minutes: 30
env:
# The husky hooks are a developer safety net; CI has its own gates. Without
# this, the full install wires the hooks and the pre-push hook runs the TS
# compile/lint (and, when the remote branch doesn't exist yet, the Rust
# clippy/doc sweep) during the action's push.
HUSKY: 0
steps:
- name: Checkout Commit
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# Don't persist the write-scoped token in .git/config. The full install
# below runs third-party lifecycle scripts from freshly-bumped
# dependencies; the token is only needed to push, which pnpm/update does
# through a single-use credential helper.
persist-credentials: false
# pnpm/update's install also installs the Rust dependencies, which runs
# `cargo`. Provision the pinned toolchain up front so that install does not
# race a rustup download.
- name: Initialize Rust before dependency installation
uses: $/.github/actions/rustup
with:
restore-cache: false
# pnpm/update runs the install itself, so the action's auto-install would
# be wasted work.
- name: Install pnpm
uses: pnpm/setup@703c52620218391530e48b9e8870d5c0082e1b9b # v2.1.0
with:
install: false
- name: Update dependencies, Node.js, pnpm, and GitHub Actions
uses: pnpm/update@fcaa952ef94bad62067a94ac2e5c6234b648e259 #v0.0.0 v0
with:
update-deps: latest
refresh-lockfile: true
github-actions: true
update-pnpm: next-12
# Follow next-12 as soon as a release is published: pnpm 12's default
# 24-hour minimumReleaseAge would otherwise hold a same-day release
# back from self-update (the repo's minimumReleaseAgeExclude is
# deliberately ignored there).
update-pnpm-minimum-release-age: 0
post-update: pnpm update-manifests
branch: chore/update-lockfile
token: ${{ secrets.UPDATE_LOCKFILE_TOKEN }}
commit-message: 'chore: update dependencies, Node.js, pnpm, and GitHub Actions'
pr-title: 'chore: update dependencies, Node.js, pnpm, and GitHub Actions'
pr-body: |
This automated PR bumps the project's dependencies and pinned versions:
- Updates all dependencies to their latest versions and refreshes the lockfile.
- Bumps Node.js to the latest 26.x release, propagated into the CI, release, and benchmark workflows via the meta-updater.
- Bumps pnpm to the latest `next-12` release (`packageManager` and `devEngines.packageManager`).
- Updates the GitHub Actions pinned in the workflow files.
Created by the [pnpm/update](https://github.com/pnpm/update) action.