Skip to content

chore: manage dependencies with pnpm - #2

Merged
studiolxd merged 5 commits into
mainfrom
chore/pnpm
Sep 20, 2026
Merged

studiolxd merged 5 commits into
mainfrom
chore/pnpm

Conversation

@studiolxd

Copy link
Copy Markdown
Owner

Summary

Moves dependency management from npm to pnpm. Publishing is untouched: releases still go out with npm publish from packages/xapi, and the Angular smoke test still packs with npm pack, so it validates the exact artefact npm will publish.

The lockfile was produced with pnpm import, so every resolved version is inherited from package-lock.json rather than re-resolved. That was the precondition for the verification below to mean anything.

Verification

Check Result
Packed tarball vs. what is published on npmjs.com 52/53 files byte-identical; the only delta is the one line below
Build-critical dependency versions unchanged
example resolves the library symlink to packages/xapi, not the registry
Example bundle same content hash and size (index-DmlwNp61.js, 263.65 kB) — rules out a duplicate React
Typecheck / tests clean / 122 passing
Angular AOT smoke against the packed tarball builds

The single tarball difference is the newly declared rxjs devDependency:

+    "rxjs": "^7.8.0",

@angular/core declares rxjs as a peer and tests/adapters/angular.test.ts pulls it in at runtime, but it was never declared here — npm's flat node_modules hoisted it so it happened to resolve. pnpm does not hoist, so it has to be explicit. scorm already declared it; this brings the twin repos back in line. devDependencies are never installed by consumers, so the published contract is unaffected.

Notes

  • tests/angular-smoke stays on npm and outside the workspace: it stands in for a real downstream consumer, and @angular-devkit/build-angular expects a flat node_modules.
  • example/package.json moves to workspace:*. With a plain *, pnpm resolved it to the published 1.0.0 from the registry instead of the local package — a silent failure that would have meant building the demo against stale code. example/vercel.json had to migrate in the same commit, since its npm install cannot parse the workspace: protocol.
  • package-lock.json is deleted in its own isolated commit, so reverting just that commit restores it intact.

Test plan

  • CI passes on Node 20 and 22
  • angular-smoke passes
  • Vercel preview opens and works in the browser — a duplicate React only shows at runtime

🤖 Generated with Claude Code

https://claude.ai/code/session_011kohSPc6KNpFd9EiV8Vbez

studiolxd and others added 5 commits September 20, 2026 11:32
@angular/core declares rxjs as a peer dependency, and tests/adapters/angular.test.ts
exercises Injector.create / runInInjectionContext, which pulls it in at runtime. It
was never declared here: npm's flat node_modules hoisted it, so it happened to
resolve. pnpm's isolated layout does not hoist, so it has to be explicit.

scorm already declares it; this brings the twin repos back in line. devDependencies
are not installed by consumers, so this does not affect the published contract.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011kohSPc6KNpFd9EiV8Vbez
Replaces npm with pnpm for dependency management across the monorepo. Publishing
is untouched: releases still go out with `npm publish` from packages/<lib>, and
the Angular smoke test still packs with `npm pack` so it validates the exact
artefact npm will publish.

The lockfile was produced with `pnpm import`, so every resolved version is
inherited from package-lock.json rather than re-resolved. Verified: the packed
tarball is byte-identical to what is published on npmjs.com (same sha256 for
scorm; for xapi the only delta is the newly declared rxjs devDependency), the
example bundles keep the same content hash and size, and the Angular AOT smoke
test still builds against the packed tarball.

This also removes three workarounds for npm defects that CI had accumulated:
the npm/cli#4828 lockfile hack (a macOS-generated lockfile made npm skip the
Linux rollup binary), the arborist `edgesOut` crash on workspace installs, and
the npm version pin those required. pnpm records every platform variant in the
lockfile and filters at install time.

tests/angular-smoke stays on npm and outside the workspace: it stands in for a
real downstream consumer, and @angular-devkit/build-angular expects a flat
node_modules.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011kohSPc6KNpFd9EiV8Vbez
Isolated on purpose: reverting this single commit restores the npm lockfile
intact if the pnpm migration needs to be rolled back.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011kohSPc6KNpFd9EiV8Vbez
Only development commands change. Installing the published package and releasing
it stay on npm, so `npm install @studiolxd/...` in the package READMEs and the
`npm publish` release steps are left alone.

Also documents why tests/angular-smoke stays on npm and outside the workspace,
and warns about the leftover-tarball trap in its manual run instructions.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011kohSPc6KNpFd9EiV8Vbez
pnpm 11 requires Node >= 22.13, so the Node 20 matrix entry could not even start
it. GitHub is deprecating Node 20 on its runners anyway, and Node 20 reached end
of life earlier this year.

This only affects the build environment; the published package declares no
engines constraint and its output does not depend on the Node version that built
it (verified: the tarball built locally on Node 26 is byte-identical to the one
published from an older toolchain).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011kohSPc6KNpFd9EiV8Vbez
@studiolxd
studiolxd merged commit c5a7a70 into main Sep 20, 2026
3 checks passed
@studiolxd
studiolxd deleted the chore/pnpm branch September 20, 2026 09:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant