Skip to content

build(deps): bump pnpm/setup from 2 to 3 in /.github/actions/setup-workspace - #830

Merged
ScriptedAlchemy merged 5 commits into
mainfrom
dependabot/github_actions/dot-github/actions/setup-workspace/pnpm/setup-3
Sep 25, 2026
Merged

ScriptedAlchemy merged 5 commits into
mainfrom
dependabot/github_actions/dot-github/actions/setup-workspace/pnpm/setup-3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Bumps pnpm/setup from 2 to 3.

Release notes

Sourced from pnpm/setup's releases.

v3.0.0

What's Changed

New Contributors

Full Changelog: pnpm/setup@v2.1.0...v3.0.0

v2.1.0

What's Changed

New Contributors

Full Changelog: pnpm/setup@v2.0.2...v2.1.0

v2.0.2

What's Changed

Full Changelog: pnpm/setup@v2.0.1...v2.0.2

v2.0.1

What's Changed

New Contributors

Full Changelog: pnpm/setup@v2.0.0...v2.0.1

Commits
  • fbda4c8 docs(README): update version
  • c868a7d fix: require-lockfile no longer accepts a lockfile pnpm will not use (#60)
  • 463911b fix: avoid deprecated shell spawning for pnpm commands (#52)
  • 6598286 docs: add private registry authentication recipes (#61)
  • c5b2e24 feat!: automatically detect Node.js version files (#49)
  • f37adde fix!: include runid in cache key, restore freshest lockfile match (#43)
  • 703c526 chore: update dependencies (#42)
  • e02cd34 ci: update dependencies with pnpm/update instead of Dependabot (#41)
  • 0080eca feat: add a require-lockfile input (#23)
  • 3327d57 feat: add working-directory, deprecating package-json-file (#27)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Root verification verdict: PASS+NOTES at bc826dad3c

Base b0b131bbf7, head bc826dad3c. main has since moved to 96b2519513 (#826). Both PRs edit docs/local-ci.md, but on different lines. git merge-tree merges cleanly onto 96b2519513, and the merged diff has the same stable patch-id (f3e22927df) as the PR diff. The verdict pins that patch-id.

The real surface of this change is CI itself, so the lanes read the PR's own CI runs against the latest green main run (35403567867, still on pnpm/setup@v2).

Lane Model Result
Per-job facts from 12 PR job logs and 16 main job logs Grok 4.7 (log collection only) Every PR job ran pnpm/setup@v3 (fbda4c85fc2e). Node matched the requested version on every leg. That is 22.19.0 on all host and gate jobs, 24.21.0 on the Node 24 legs, and 26.10.0 on the Node 26 leg. pnpm stayed 11.23.0. The retry step never ran.
Input list and auto-detect check root The comment's input list matches pnpm/setup@v3's action.yml exactly. v3's Node version-file auto-detection applies only when no version is given. This action always passes runtime, so the matrix is not collapsed. The logs confirm it.
Regression vs main root Same Node and pnpm versions per leg as main. Every PR job restored the v2-era store through the new restore prefix, so the first run after the bump is a cache hit.

Note, not blocking:

  • v3 puts the run id, attempt, and a UUID in the cache key. Every job now saves its own copy of the pnpm store, about 190 MB on Linux and macOS and 152 MB on Windows, and the save adds about 5 to 8 s per job. On v2 a hit saved nothing. The two CI runs of this PR alone wrote 23 entries totalling 4.46 GB. The repository's active cache is at 7.4 GB of GitHub's default 10 GB. After merge each main push and each PR run writes a similar batch, so LRU eviction will churn constantly. Restores still hit through the prefix, so the likely cost is storage churn and occasional cold installs, not failures. That cost is a prediction from these numbers, not yet observed. A follow-up could save from one job per OS, or accept the churn.

CI at this head is green (mergeStateStatus CLEAN).


Maintainer notes

pnpm/setup v3 breaking changes checked against .github/actions/setup-workspace:

  • Node version-file auto-detection. Every consumer passes an explicit runtime: node@<version>, which v3 ranks above version files.
  • Cache key now includes the run id. Restores use the freshest lockfile match. The inputs used here (cache, install, runtime) are unchanged, and no workflow reads steps.setup.outputs.* or cache-hit. The retry on steps.setup.outcome still works.
  • Updated text. I changed the action's comments, description, retry warning, and docs/local-ci.md to v3, and added v3's node-version-file input to the listed inputs. The 2026-09-04 incident lines stay v2 because they are history.

CI on bc826da was fully green. In the Verify (fast, Node 26) log, pnpm/setup@v3 ran with runtime: node@26 and installed node@26. The store restored from a restore-key, and the post step saved a new per-run cache in about 5 s. Later heads only merge main (#825, #826, #817). CI-only change, so no changeset.

Independent review (change-risk-reviewer, GPT-5.6 Sol Max) found no blockers and one should-fix: v3 saves a new store cache (about 195 MB) from every setup invocation. The repo was at 7.4 GB of the 10 GB cache quota. Accepted, with follow-up: GitHub evicts least-recently-accessed entries first, so the caches every run restores survive. Watch cache usage after merge, and switch fan-out jobs to restore-only if eviction starts to hurt.

Bumps [pnpm/setup](https://github.com/pnpm/setup) from 2 to 3.
- [Release notes](https://github.com/pnpm/setup/releases)
- [Commits](pnpm/setup@v2...v3)

---
updated-dependencies:
- dependency-name: pnpm/setup
  dependency-version: '3'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 23, 2026
@changeset-bot

changeset-bot Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 4bf9fd0

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@pkg-pr-new

pkg-pr-new Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
npm i https://pkg.pr.new/ScriptedAlchemy/agent-bundle@830
npm i https://pkg.pr.new/ScriptedAlchemy/agent-bundle/create-agent-bundle@830
npm i https://pkg.pr.new/ScriptedAlchemy/agent-bundle/rsc-markdown-stream@830
npm i https://pkg.pr.new/ScriptedAlchemy/agent-bundle/@agent-bundle/runtime@830

commit: 6f1f263

@ScriptedAlchemy
ScriptedAlchemy merged commit 0dad46c into main Sep 25, 2026
3 checks passed
@dependabot
dependabot Bot deleted the dependabot/github_actions/dot-github/actions/setup-workspace/pnpm/setup-3 branch September 25, 2026 00:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant