chore: manage dependencies with pnpm - #2
Merged
Merged
Conversation
@angular/core declares rxjs as a peer dependency, and tests/adapters/angular.test.ts exercises Injector.create / runInInjectionContext, which pulls it in at runtime. It was never declared here: npm's flat node_modules hoisted it, so it happened to resolve. pnpm's isolated layout does not hoist, so it has to be explicit. scorm already declares it; this brings the twin repos back in line. devDependencies are not installed by consumers, so this does not affect the published contract. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011kohSPc6KNpFd9EiV8Vbez
Replaces npm with pnpm for dependency management across the monorepo. Publishing is untouched: releases still go out with `npm publish` from packages/<lib>, and the Angular smoke test still packs with `npm pack` so it validates the exact artefact npm will publish. The lockfile was produced with `pnpm import`, so every resolved version is inherited from package-lock.json rather than re-resolved. Verified: the packed tarball is byte-identical to what is published on npmjs.com (same sha256 for scorm; for xapi the only delta is the newly declared rxjs devDependency), the example bundles keep the same content hash and size, and the Angular AOT smoke test still builds against the packed tarball. This also removes three workarounds for npm defects that CI had accumulated: the npm/cli#4828 lockfile hack (a macOS-generated lockfile made npm skip the Linux rollup binary), the arborist `edgesOut` crash on workspace installs, and the npm version pin those required. pnpm records every platform variant in the lockfile and filters at install time. tests/angular-smoke stays on npm and outside the workspace: it stands in for a real downstream consumer, and @angular-devkit/build-angular expects a flat node_modules. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011kohSPc6KNpFd9EiV8Vbez
Isolated on purpose: reverting this single commit restores the npm lockfile intact if the pnpm migration needs to be rolled back. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011kohSPc6KNpFd9EiV8Vbez
Only development commands change. Installing the published package and releasing it stay on npm, so `npm install @studiolxd/...` in the package READMEs and the `npm publish` release steps are left alone. Also documents why tests/angular-smoke stays on npm and outside the workspace, and warns about the leftover-tarball trap in its manual run instructions. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011kohSPc6KNpFd9EiV8Vbez
pnpm 11 requires Node >= 22.13, so the Node 20 matrix entry could not even start it. GitHub is deprecating Node 20 on its runners anyway, and Node 20 reached end of life earlier this year. This only affects the build environment; the published package declares no engines constraint and its output does not depend on the Node version that built it (verified: the tarball built locally on Node 26 is byte-identical to the one published from an older toolchain). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011kohSPc6KNpFd9EiV8Vbez
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Moves dependency management from npm to pnpm. Publishing is untouched: releases still go out with
npm publishfrompackages/xapi, and the Angular smoke test still packs withnpm pack, so it validates the exact artefact npm will publish.The lockfile was produced with
pnpm import, so every resolved version is inherited frompackage-lock.jsonrather than re-resolved. That was the precondition for the verification below to mean anything.Verification
exampleresolves the librarypackages/xapi, not the registryindex-DmlwNp61.js, 263.65 kB) — rules out a duplicate ReactThe single tarball difference is the newly declared
rxjsdevDependency:+ "rxjs": "^7.8.0",@angular/coredeclaresrxjsas a peer andtests/adapters/angular.test.tspulls it in at runtime, but it was never declared here — npm's flatnode_moduleshoisted it so it happened to resolve. pnpm does not hoist, so it has to be explicit.scormalready declared it; this brings the twin repos back in line. devDependencies are never installed by consumers, so the published contract is unaffected.Notes
tests/angular-smokestays on npm and outside the workspace: it stands in for a real downstream consumer, and@angular-devkit/build-angularexpects a flatnode_modules.example/package.jsonmoves toworkspace:*. With a plain*, pnpm resolved it to the published 1.0.0 from the registry instead of the local package — a silent failure that would have meant building the demo against stale code.example/vercel.jsonhad to migrate in the same commit, since itsnpm installcannot parse theworkspace:protocol.package-lock.jsonis deleted in its own isolated commit, so reverting just that commit restores it intact.Test plan
angular-smokepasses🤖 Generated with Claude Code
https://claude.ai/code/session_011kohSPc6KNpFd9EiV8Vbez