The client/ package.json now has @galaxyproject/galaxy-api-client at
workspace:* and a postinstall that filters into the workspace to build
it. npm publish doesn't rewrite the workspace: protocol, so the published
tarball would carry the literal "workspace:*" and break downstream
installs; pnpm publish substitutes the real version. The postinstall is
also workspace-only -- if it ships in the tarball, consumers' npm install
fails when pnpm --filter runs outside any workspace -- so npm pkg delete
strips it before pnpm publish runs.