From 8a6ecbb422f2aad5006db75e51a79207d8c36494 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 23 Sep 2026 14:24:33 +0000 Subject: [PATCH 1/2] build(deps): bump pnpm/setup in /.github/actions/setup-workspace Bumps [pnpm/setup](https://github.com/pnpm/setup) from 2 to 3. - [Release notes](https://github.com/pnpm/setup/releases) - [Commits](https://github.com/pnpm/setup/compare/v2...v3) --- updated-dependencies: - dependency-name: pnpm/setup dependency-version: '3' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] --- .github/actions/setup-workspace/action.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/actions/setup-workspace/action.yml b/.github/actions/setup-workspace/action.yml index 822e3ab5f..8a46015c2 100644 --- a/.github/actions/setup-workspace/action.yml +++ b/.github/actions/setup-workspace/action.yml @@ -68,7 +68,7 @@ runs: steps: - name: Set up pnpm and Node.js id: setup - uses: pnpm/setup@v2 + uses: pnpm/setup@v3 continue-on-error: true with: cache: true @@ -85,7 +85,7 @@ runs: - name: Set up pnpm and Node.js (retry) if: steps.setup.outcome == 'failure' - uses: pnpm/setup@v2 + uses: pnpm/setup@v3 with: cache: true install: false From bc826dad3c631c9ca24d5442467aa66d3b183b40 Mon Sep 17 00:00:00 2001 From: ScriptedAlchemy Date: Thu, 24 Sep 2026 23:37:31 +0000 Subject: [PATCH 2/2] ci: describe setup-workspace against pnpm/setup v3 --- .github/actions/setup-workspace/action.yml | 16 ++++++++-------- docs/local-ci.md | 2 +- 2 files changed, 9 insertions(+), 9 deletions(-) diff --git a/.github/actions/setup-workspace/action.yml b/.github/actions/setup-workspace/action.yml index 8a46015c2..31fe0c554 100644 --- a/.github/actions/setup-workspace/action.yml +++ b/.github/actions/setup-workspace/action.yml @@ -1,4 +1,4 @@ -# Set up workspace: pnpm + Node.js via pnpm/setup@v2, then +# Set up workspace: pnpm + Node.js via pnpm/setup@v3, then # `pnpm install --frozen-lockfile`, each with a bounded retry. # # Why this exists (#576, flake table): on 2026-09-04 `pnpm/setup@v2` failed @@ -7,11 +7,11 @@ # Gateway Timeout` / `fetch failed` — and every one was green on rerun. The # action downloads pnpm's executable from the npm registry as its very first # network call and exposes no retry input (its inputs are `version`, `dest`, -# `runtime`, `cache`, `cache-dependency-path`, `working-directory`, -# `package-json-file`, `require-lockfile`, `install`, `token`), so the retry -# lives here instead of in every job: +# `runtime`, `node-version-file`, `cache`, `cache-dependency-path`, +# `working-directory`, `package-json-file`, `require-lockfile`, `install`, +# `token`), so the retry lives here instead of in every job: # -# 1. `pnpm/setup@v2` with `continue-on-error`; on failure, wait 15 s and run +# 1. `pnpm/setup@v3` with `continue-on-error`; on failure, wait 15 s and run # it once more. The second attempt is not `continue-on-error`, so a # second failure fails the job. (`steps..outcome` is the result # before `continue-on-error` is applied, so it reads `failure` for a @@ -47,13 +47,13 @@ # `actions/checkout` must run before it. name: Set up workspace description: >- - Install pnpm and Node.js with pnpm/setup@v2 (retried once on failure), run + Install pnpm and Node.js with pnpm/setup@v3 (retried once on failure), run `pnpm install --frozen-lockfile` (up to three attempts), and optionally install a Playwright browser. inputs: node-version: - description: Node.js version for pnpm/setup@v2's `runtime` input, e.g. `22.19.0`, `24`, `26`. + description: Node.js version for pnpm/setup@v3's `runtime` input, e.g. `22.19.0`, `24`, `26`. required: true playwright-browser: description: >- @@ -80,7 +80,7 @@ runs: shell: bash run: | set -euo pipefail - echo "::warning::pnpm/setup@v2 failed on the first attempt (registry 5xx or network error?); retrying in 15 s." + echo "::warning::pnpm/setup@v3 failed on the first attempt (registry 5xx or network error?); retrying in 15 s." sleep 15 - name: Set up pnpm and Node.js (retry) diff --git a/docs/local-ci.md b/docs/local-ci.md index 977edfe47..0c0725700 100644 --- a/docs/local-ci.md +++ b/docs/local-ci.md @@ -246,7 +246,7 @@ then treat a repeat as a real signal. - **Registry 5xx while setting up the job.** Every hosted job installs pnpm, Node, and dependencies through the shared `.github/actions/setup-workspace` - action. `pnpm/setup@v2` downloads the pnpm executable from the npm registry + action. `pnpm/setup@v3` downloads the pnpm executable from the npm registry as its first network call and exposes no retry input, so the action retries it once after 15 s, then runs `pnpm install --frozen-lockfile` up to three times (10 s, then 20 s back-off). A persistent outage still fails the job