Skip to content

Enforce the pnpm-only and hoisted-linker rules in CI - #7

Open
XxHugheadxX wants to merge 1 commit into
mainfrom
chore/ci-guardrails
Open

XxHugheadxX wants to merge 1 commit into
mainfrom
chore/ci-guardrails

Conversation

@XxHugheadxX

Copy link
Copy Markdown
Contributor

One new CI job. Touches no source, no tests, no dependencies.

Why

Two rules are written down in AGENTS.md and the team plan, and nothing checks either one. One has already been broken.

A 260 KB frontend/package-lock.json reached main. The plan warned about exactly this in §2.5 — pear stage bundles by walking node_modules and depends on the hoisted layout, so an npm or yarn install here is the documented cause of "works in dev, missing in the binary". It sat there because the rule lived only in a document.

What it checks

  1. No npm or yarn lockfile is tracked. Uses git ls-files, so node_modules is irrelevant and the check is exact.
  2. nodeLinker: hoisted is still set. Reads pnpm-workspace.yaml, not .npmrc — pnpm >= 10.6 ignores node-linker in .npmrc entirely, and the workspace file is the one that actually takes effect. The comment in .npmrc says so itself.

Both messages explain the consequence and the fix, not just that something failed.

The job needs no install, so a violation fails in seconds rather than behind the six-platform matrix.

This PR will be red until #5 lands, on purpose

frontend/package-lock.json is still on main right now, so check 1 fails — which is the check finding a real violation that exists today. #5 deletes that file; once it merges, this goes green.

I'd rather show the guard catching the thing it was built for than quietly bundle the deletion in here and have you take my word for it.

Not in scope

Cross-platform coverage for the new LAN discovery tests needed nothing: the existing build job already runs pnpm test on all six targets, so those tests get Linux, macOS and Windows automatically once F1 lands.

🤖 Generated with Claude Code

https://claude.ai/code/session_01V9zUvsS38fU1M1hT9yFK6j

Both are written down in AGENTS.md and the team plan, and nothing checked
either. One has already been broken: a 260KB frontend/package-lock.json
reached main, which is the documented cause of "works in dev, missing in
the binary" -- pear stage bundles by walking node_modules and depends on
the hoisted layout.

The linker check reads pnpm-workspace.yaml rather than .npmrc, since
pnpm >=10.6 ignores node-linker there and the workspace file is the one
that takes effect.

Needs no install, so it fails in seconds instead of behind a six-platform
matrix. Note this job fails on main today: the phantom lockfile is still
there until the F0 branch lands, which is the check doing its job.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V9zUvsS38fU1M1hT9yFK6j

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant