chore: Move CI and repo configurations to use pnpm 11 (#36424)

This commit is contained in:
Matsu
2026-08-25 09:09:09 +03:00
committed by GitHub
parent 7821b9c5b7
commit f6b4e48d32
21 changed files with 3213 additions and 2054 deletions
+82 -106
View File
@@ -1,7 +1,7 @@
{
"version": 1,
"generated": "2026-07-22T13:28:07.821Z",
"totalViolations": 188,
"generated": "2026-08-24T09:15:32.266Z",
"totalViolations": 184,
"violations": {
"packages/@n8n/ai-workflow-builder.ee/package.json": [
{
@@ -549,12 +549,6 @@
"line": 30,
"message": "stylelint appears in 2 packages with 2 different versions — add to pnpm-workspace.yaml catalog",
"hash": "955f3fe044c7"
},
{
"rule": "catalog-violations",
"line": 46,
"message": "stylelint appears in 2 packages with 2 different versions — add to pnpm-workspace.yaml catalog",
"hash": "955f3fe044c7"
}
],
"packages/@n8n/db/src/migrations/common/1690000000030-RemoveResetPasswordColumns.ts": [
@@ -1053,98 +1047,6 @@
"hash": "ac2493848228"
}
],
"package.json": [
{
"rule": "stale-overrides",
"line": 107,
"message": "Override \"@azure/identity\" duplicates a catalog entry for @azure/identity — set the override to \"catalog:\" or remove it",
"hash": "ef24d04a4347"
},
{
"rule": "stale-overrides",
"line": 108,
"message": "Override \"@lezer/common\" duplicates a catalog entry for @lezer/common — set the override to \"catalog:\" or remove it",
"hash": "1e5d2fb72ef8"
},
{
"rule": "stale-overrides",
"line": 111,
"message": "Override \"@types/node\" duplicates a catalog entry for @types/node — set the override to \"catalog:\" or remove it",
"hash": "d3577ed2e92d"
},
{
"rule": "stale-overrides",
"line": 112,
"message": "Override \"chokidar\" duplicates a catalog entry for chokidar — set the override to \"catalog:\" or remove it",
"hash": "8496c5755ef0"
},
{
"rule": "stale-overrides",
"line": 122,
"message": "Override \"vue-tsc\" duplicates a catalog entry for vue-tsc — set the override to \"catalog:frontend\" or remove it",
"hash": "5414a6c2842f"
},
{
"rule": "stale-overrides",
"line": 128,
"message": "Override \"form-data\" duplicates a catalog entry for form-data — set the override to \"catalog:\" or remove it",
"hash": "ec13014b18ab"
},
{
"rule": "stale-overrides",
"line": 131,
"message": "Override \"nodemailer\" duplicates a catalog entry for nodemailer — set the override to \"catalog:\" or remove it",
"hash": "1a696378ebfc"
},
{
"rule": "stale-overrides",
"line": 133,
"message": "Override \"zod\" duplicates a catalog entry for zod — set the override to \"catalog:\" or remove it",
"hash": "6224a1e7997d"
},
{
"rule": "stale-overrides",
"line": 142,
"message": "Override \"@rudderstack/rudder-sdk-node@<=3.0.0\" duplicates a catalog entry for @rudderstack/rudder-sdk-node — set the override to \"catalog:\" or remove it",
"hash": "71f703e2c449"
},
{
"rule": "stale-overrides",
"line": 153,
"message": "Override \"lodash\" duplicates a catalog entry for lodash — set the override to \"catalog:\" or remove it",
"hash": "3cbb69cc0ff8"
},
{
"rule": "stale-overrides",
"line": 161,
"message": "Override \"flatted\" duplicates a catalog entry for flatted — set the override to \"catalog:\" or remove it",
"hash": "7fe03ed5fec2"
},
{
"rule": "stale-overrides",
"line": 170,
"message": "Override \"yaml@<=2.8.3\" duplicates a catalog entry for yaml — set the override to \"catalog:\" or remove it",
"hash": "a5ab421c217c"
},
{
"rule": "stale-overrides",
"line": 171,
"message": "Override \"axios\" duplicates a catalog entry for axios — set the override to \"catalog:\" or remove it",
"hash": "3bd62181cb8d"
},
{
"rule": "stale-overrides",
"line": 175,
"message": "Override \"uuid@<=13.0.1\" duplicates a catalog entry for uuid — set the override to \"catalog:\" or remove it",
"hash": "abd23b6d69fe"
},
{
"rule": "stale-overrides",
"line": 184,
"message": "Override \"langsmith\" duplicates a catalog entry for langsmith — set the override to \"catalog:\" or remove it",
"hash": "170e854b445c"
}
],
"packages/@n8n/typeorm/package.json": [
{
"rule": "catalog-violations",
@@ -1205,12 +1107,6 @@
"line": 87,
"message": "typescript@^5.3.3 should use \"catalog:\" (exists in pnpm-workspace.yaml)",
"hash": "050d5b2d74e1"
},
{
"rule": "catalog-violations",
"line": 90,
"message": "pg@^8.17.0 should use \"catalog:\" (exists in pnpm-workspace.yaml)",
"hash": "6cac348bdcc8"
}
],
"packages/core/package.json": [
@@ -1328,6 +1224,86 @@
"message": "\"zod\" is a runtime dependency of \"@n8n/telemetry\"; it must be a peerDependency.",
"hash": "d61edcda4afe"
}
],
"pnpm-workspace.yaml": [
{
"rule": "stale-overrides",
"line": 327,
"message": "Override \"@azure/identity\" duplicates a catalog entry for @azure/identity — set the override to \"catalog:\" or remove it",
"hash": "5183952df723"
},
{
"rule": "stale-overrides",
"line": 328,
"message": "Override \"@lezer/common\" duplicates a catalog entry for @lezer/common — set the override to \"catalog:\" or remove it",
"hash": "6aa79f7cd1ba"
},
{
"rule": "stale-overrides",
"line": 334,
"message": "Override \"@types/node\" duplicates a catalog entry for @types/node — set the override to \"catalog:\" or remove it",
"hash": "e25412bfd766"
},
{
"rule": "stale-overrides",
"line": 335,
"message": "Override \"chokidar\" duplicates a catalog entry for chokidar — set the override to \"catalog:\" or remove it",
"hash": "b6002f782205"
},
{
"rule": "stale-overrides",
"line": 350,
"message": "Override \"form-data\" duplicates a catalog entry for form-data — set the override to \"catalog:\" or remove it",
"hash": "76d57eeb42b2"
},
{
"rule": "stale-overrides",
"line": 354,
"message": "Override \"nodemailer\" duplicates a catalog entry for nodemailer — set the override to \"catalog:\" or remove it",
"hash": "9ce0ecb14ba5"
},
{
"rule": "stale-overrides",
"line": 356,
"message": "Override \"zod\" duplicates a catalog entry for zod — set the override to \"catalog:\" or remove it",
"hash": "6dad5def0c97"
},
{
"rule": "stale-overrides",
"line": 366,
"message": "Override \"@rudderstack/rudder-sdk-node@<=3.0.0\" duplicates a catalog entry for @rudderstack/rudder-sdk-node — set the override to \"catalog:\" or remove it",
"hash": "413eaaefa630"
},
{
"rule": "stale-overrides",
"line": 374,
"message": "Override \"lodash\" duplicates a catalog entry for lodash — set the override to \"catalog:\" or remove it",
"hash": "58cfd2a6213b"
},
{
"rule": "stale-overrides",
"line": 381,
"message": "Override \"flatted\" duplicates a catalog entry for flatted — set the override to \"catalog:\" or remove it",
"hash": "bc9ce009bac8"
},
{
"rule": "stale-overrides",
"line": 390,
"message": "Override \"yaml@<=2.8.3\" duplicates a catalog entry for yaml — set the override to \"catalog:\" or remove it",
"hash": "9434ddd428c5"
},
{
"rule": "stale-overrides",
"line": 396,
"message": "Override \"uuid@<=13.0.1\" duplicates a catalog entry for uuid — set the override to \"catalog:\" or remove it",
"hash": "1a45449bfde3"
},
{
"rule": "stale-overrides",
"line": 409,
"message": "Override \"langsmith\" duplicates a catalog entry for langsmith — set the override to \"catalog:\" or remove it",
"hash": "9ac3dbae3d22"
}
]
}
}
+5 -1
View File
@@ -31,7 +31,11 @@ runs:
using: 'composite'
steps:
- name: Setup pnpm
uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1 # v4.3.0
uses: pnpm/setup@84cb39b217b10273981911c288cd62326dc7c6d2 # v2.0.2
with:
install: false
version: 11.22.0
cache-dependency-path: ${{ inputs.cache-dependency-path }}
# Cache the Node toolcache so setup-node skips the ~33s nodejs.org download
# on every subsequent job. First fresh runner pays the download; later jobs
+16 -9
View File
@@ -23,11 +23,17 @@ export function generateExperimentalVersion(currentVersion, sha) {
}
/**
* Overrides live in `pnpm-workspace.yaml` since pnpm 11; older tags still carry them in
* package.json. Both are merged so a comparison that straddles the move sees the same set
* on either side, rather than reading every override as added and removed.
*
* @param {{ pnpm?: { overrides?: Record<string, string> }, overrides?: Record<string, string> }} pkg
* @param {Record<string, unknown>} [workspace] parsed pnpm-workspace.yaml
* @returns {Record<string, string>}
*/
export function getOverrides(pkg) {
return { ...pkg.pnpm?.overrides, ...pkg.overrides };
export function getOverrides(pkg, workspace) {
const fromWorkspace = /** @type {Record<string, string> | undefined} */ (workspace?.overrides);
return { ...pkg.pnpm?.overrides, ...pkg.overrides, ...fromWorkspace };
}
/**
@@ -213,19 +219,14 @@ async function bumpVersions() {
// that package also needs a bump (e.g. design-system → editor-ui → cli).
// Detect root-level changes that affect resolved dep versions without touching individual
// package.json files: pnpm.overrides (applies to all specifiers)
// and pnpm-workspace.yaml catalog entries (applies only to deps using a "catalog:…" specifier).
// package.json files: overrides (apply to all specifiers) and catalog entries
// (apply only to deps using a "catalog:…" specifier).
const rootPkgJson = JSON.parse(await readFile(resolve(rootDir, 'package.json'), 'utf-8'));
const rootPkgJsonAtTag = await exec(`git show ${lastTag}:package.json`)
.then(({ stdout }) => JSON.parse(stdout))
.catch(() => ({}));
const changedOverrides = computeChangedOverrides(
getOverrides(rootPkgJson),
getOverrides(rootPkgJsonAtTag),
);
const workspaceYaml = parseWorkspaceYaml(
await readFile(resolve(rootDir, 'pnpm-workspace.yaml'), 'utf-8').catch(() => ''),
);
@@ -234,6 +235,12 @@ async function bumpVersions() {
.then(({ stdout }) => stdout)
.catch(() => ''),
);
const changedOverrides = computeChangedOverrides(
getOverrides(rootPkgJson, workspaceYaml),
getOverrides(rootPkgJsonAtTag, workspaceYamlAtTag),
);
const changedCatalogEntries = computeChangedCatalogEntries(
getCatalogs(workspaceYaml),
getCatalogs(workspaceYamlAtTag),
+20
View File
@@ -72,6 +72,26 @@ describe('getOverrides', () => {
{ lodash: '^4.0.0', underscore: '^1.0.0' },
);
});
it('returns workspace overrides when package.json has none', () => {
assert.deepEqual(getOverrides({}, { overrides: { lodash: '^4.0.0' } }), { lodash: '^4.0.0' });
});
it('lets workspace overrides win over package.json for the same key', () => {
assert.deepEqual(
getOverrides(
{ pnpm: { overrides: { lodash: '^3.0.0', underscore: '^1.0.0' } } },
{ overrides: { lodash: '^4.0.0' } },
),
{ lodash: '^4.0.0', underscore: '^1.0.0' },
);
});
it('sees no change when an override only moves from package.json to the workspace file', () => {
const atTag = getOverrides({ pnpm: { overrides: { lodash: '^4.0.0' } } }, {});
const current = getOverrides({}, { overrides: { lodash: '^4.0.0' } });
assert.deepEqual(computeChangedOverrides(current, atTag), new Set());
});
});
describe('parseWorkspaceYaml', () => {
+6 -6
View File
@@ -1,5 +1,10 @@
{
"name": "workflow-scripts",
"engines": {
"node": ">=24.0.0",
"pnpm": ">=11.22.0"
},
"packageManager": "pnpm@11.22.0",
"scripts": {
"test": "node --test --experimental-test-module-mocks ./*.test.mjs ./quality/*.test.mjs ./slack/*.test.mjs ./stale/*.test.mjs ../../scripts/licenses/*.test.mjs ../../scripts/mutation-health/*.test.mjs",
"generate-sbom": "FETCH_LICENSE=true cdxgen -t pnpm --no-install-deps --profile license-compliance --spec-version 1.6 -o ../../sbom-source.cdx.json ../../compiled/",
@@ -14,6 +19,7 @@
"@octokit/core": "7.0.6",
"conventional-changelog": "7.2.0",
"debug": "4.4.3",
"json-with-bigint": "3.5.11",
"glob": "13.0.6",
"minimatch": "10.2.4",
"semver": "7.7.4",
@@ -22,11 +28,5 @@
},
"devDependencies": {
"conventional-changelog-angular": "8.3.0"
},
"pnpm": {
"overrides": {
"brace-expansion@5": "5.0.9",
"fast-uri@3": "3.1.4"
}
}
}
+134 -128
View File
@@ -4,10 +4,6 @@ settings:
autoInstallPeers: true
excludeLinksFromLockfile: false
overrides:
brace-expansion@5: 5.0.9
fast-uri@3: 3.1.4
importers:
.:
@@ -30,6 +26,9 @@ importers:
glob:
specifier: 13.0.6
version: 13.0.6
json-with-bigint:
specifier: 3.5.11
version: 3.5.11
minimatch:
specifier: 10.2.4
version: 10.2.4
@@ -41,7 +40,7 @@ importers:
version: 6.0.1
yaml:
specifier: ^2.8.3
version: 2.8.3
version: 2.9.0
devDependencies:
conventional-changelog-angular:
specifier: 8.3.0
@@ -76,8 +75,8 @@ packages:
resolution: {integrity: sha512-Aup7aUOfpbAUg2ROOJN6Iw5f9DMBlzu0mIkm/malLQFN/YQgO48wCj0Kxa3sEHJvPVFg7siR+qRInwXd2qhQKw==}
engines: {node: '>=6.9.0'}
'@babel/generator@7.29.7':
resolution: {integrity: sha512-DkXD5OJQaAQIdZ1bt3UZdEnHAn9Imd3IVBdX03UFe+ony9Ojw5pzr9YVKGDY1jt+Gcn/FnGkNf8r+Vj5NOJWtQ==}
'@babel/generator@7.29.8':
resolution: {integrity: sha512-gZbepsdh3WDtgZKWL+vTPh71LSBrm/Y4/QDZBVCcYfmeTEEuoOYwlSy+G1StfJg+/Zy550u/3TATbm7qDbbMtg==}
engines: {node: '>=6.9.0'}
'@babel/helper-globals@7.29.7':
@@ -97,8 +96,8 @@ packages:
engines: {node: '>=6.0.0'}
hasBin: true
'@babel/parser@7.29.7':
resolution: {integrity: sha512-hnORnjP/1P/zFEndoeX+n+t1RwWRJiJpM/jO7FW32Kn9r5+sJB2JWOdYo4L6k78j15eCwY3Gm/7364B1EMwtNg==}
'@babel/parser@7.29.8':
resolution: {integrity: sha512-E8lTAYNB1KW+FH+VGJuZM1ioAx2E6oVlvQFRrf5P8ZZmsiJXYAD9vTFV7yyEURNzgh1dFqMZuO6tUwcARbqFCA==}
engines: {node: '>=6.0.0'}
hasBin: true
@@ -110,8 +109,8 @@ packages:
resolution: {integrity: sha512-4HPiQr0X7+waHfyXPZpWPfWL/J7dcN1mx9gL6WdQVMbPnF3+ZhSMs8tCxN7oHddJE9fhNE7+lxdnlyemKfJRuA==}
engines: {node: '>=6.9.0'}
'@babel/types@7.29.7':
resolution: {integrity: sha512-4zBIxpPzowiZpusoFkyGVwakdRJUyuH5PxQ/PrqghfdFWWasvnCdPfQXHrenDai+gyLARulZjZowCOj6fjT4pA==}
'@babel/types@7.29.8':
resolution: {integrity: sha512-Vj1jF3cPfxg7OAfoI7QnVKLoILlm2JF9pnVHrX8qx7AHMiYWT+NDAA7jChlNgRS4WTLc/fD1lXLmPixluj+3Gg==}
engines: {node: '>=6.9.0'}
'@bufbuild/protobuf@2.12.0':
@@ -180,12 +179,12 @@ packages:
resolution: {integrity: sha512-HEAqHzwZzy3AlxguMTiIW0UmnKJDT7WTZA9NIclneLVB2qORdCZ5K4PVOTxAPwOdVId/27whQtx0nvEx0WUnkQ==}
cpu: [x64]
'@conventional-changelog/git-client@2.6.0':
resolution: {integrity: sha512-T+uPDciKf0/ioNNDpMGc8FDsehJClZP0yR3Q5MN6wE/Y/1QZ7F+80OgznnTCOlMEG4AV0LvH2UJi3C/nBnaBUg==}
'@conventional-changelog/git-client@2.7.0':
resolution: {integrity: sha512-j7A8/LBEQ+3rugMzPXoKYzyUPpw/0CBQCyvtTR7Lmu4olG4yRC/Tfkq79Mr3yuPs0SUitlO2HwGP3gitMJnRFw==}
engines: {node: '>=18'}
peerDependencies:
conventional-commits-filter: ^5.0.0
conventional-commits-parser: ^6.3.0
conventional-commits-parser: ^6.4.0
peerDependenciesMeta:
conventional-commits-filter:
optional: true
@@ -262,17 +261,20 @@ packages:
resolution: {integrity: sha512-DhGl4xMVFGVIyMwswXeyzdL4uXD5OGILGX5N8Y+f6W7LhC1Ze2poSNrkF/fedpVDHEEZ+PHFW0vL14I+mm8K3Q==}
engines: {node: '>= 20'}
'@octokit/endpoint@11.0.3':
resolution: {integrity: sha512-FWFlNxghg4HrXkD3ifYbS/IdL/mDHjh9QcsNyhQjN8dplUoZbejsdpmuqdA76nxj2xoWPs7p8uX2SNr9rYu0Ag==}
'@octokit/endpoint@11.0.4':
resolution: {integrity: sha512-f1cOWoHPmxryJFknxbtDdjODWfV8A9tc8Aae6ermXPNgHFZ/x91AtHIz4gicEjL8hkJiip+u21QHJORfBv/qiA==}
engines: {node: '>= 20'}
'@octokit/graphql@9.0.3':
resolution: {integrity: sha512-grAEuupr/C1rALFnXTv6ZQhFuL1D8G5y8CN04RgrO4FIPMrtm+mcZzFG7dcBm+nq+1ppNixu+Jd78aeJOYxlGA==}
'@octokit/graphql@9.0.4':
resolution: {integrity: sha512-5s15CCiY8XXQ+FG+b1YQcl6Z2FA++nwAz/tg2VUrTmnMncP+2nnGUEYANImdnxsA2Fnq+Mbl7hDjUTw7cFAwcg==}
engines: {node: '>= 20'}
'@octokit/openapi-types@27.0.0':
resolution: {integrity: sha512-whrdktVs1h6gtR+09+QsNk2+FO+49j6ga1c55YZudfEG+oKJVvJLQi3zkOm5JjiUXAagWK2tI2kTGKJ2Ys7MGA==}
'@octokit/openapi-types@28.0.0':
resolution: {integrity: sha512-0rFyLuyHvIj6uuZWuDslxkowFYdPXoNIkeAv4b27dzm2Tf4vGWXnPsMcxs7d65kLdMERgP3wc1AEPlqMz8e1cQ==}
'@octokit/plugin-paginate-rest@14.0.0':
resolution: {integrity: sha512-fNVRE7ufJiAA3XUrha2omTA39M6IXIc6GIZLvlbsm8QOQCYvpq/LkMNGyFlB1d8hTDzsAXa3OKtybdMAYsV/fw==}
engines: {node: '>= 20'}
@@ -285,17 +287,20 @@ packages:
peerDependencies:
'@octokit/core': '>=6'
'@octokit/request-error@7.1.0':
resolution: {integrity: sha512-KMQIfq5sOPpkQYajXHwnhjCC0slzCNScLHs9JafXc4RAJI+9f+jNDlBNaIMTvazOPLgb4BnlhGJOTbnN0wIjPw==}
'@octokit/request-error@7.1.1':
resolution: {integrity: sha512-+eaY7G2VVpSf2pc5Gn1+mph837V/d/TYTJAgWL9Tb0ogGYcpN3IlAVFgjL+Vv93F/sevrxkvsYCedtpLdcFLzA==}
engines: {node: '>= 20'}
'@octokit/request@10.0.8':
resolution: {integrity: sha512-SJZNwY9pur9Agf7l87ywFi14W+Hd9Jg6Ifivsd33+/bGUQIjNujdFiXII2/qSlN2ybqUHfp5xpekMEjIBTjlSw==}
'@octokit/request@10.0.13':
resolution: {integrity: sha512-v2269YxL9Yf+x3d+gRI63FP0vFQEiWgLyBzxe/Y+0yFDg2B/Tzf5dhh9VNfccVAQnfcfwQWyk/y6Bn7rUXXs7A==}
engines: {node: '>= 20'}
'@octokit/types@16.0.0':
resolution: {integrity: sha512-sKq+9r1Mm4efXW1FCk7hFSeJo4QKreL/tTbR0rz/qx/r1Oa2VV83LTA/H/MuCOX7uCIJmQVRKBcbmWoySjAnSg==}
'@octokit/types@17.0.0':
resolution: {integrity: sha512-ByP1v7YL5SMveFPP7+sj0/ZuWCOOg/Chs4NafOMpq6WNIM/hdGY0S7C0TCGDBWu1aGmOxmUIhMx3cO+IdwYZ1Q==}
'@sec-ant/readable-stream@0.4.1':
resolution: {integrity: sha512-831qok9r2t8AlxLko40y2ebgSDhenenCatLVeW/uBtnHPyhHOvG0C7TvfgecV+wHzIm5KUICgzmVpWS+IMEAeg==}
@@ -336,8 +341,8 @@ packages:
resolution: {integrity: sha512-quJQXlTSUGL2LH9SUXo8VwsY4soanhgo6LNSm84E1LBcE8s3O0wpdiRzyR9z/ZZJMlMWv37qOOb9pdJlMUEKFQ==}
engines: {node: '>=8'}
ansi-regex@6.2.2:
resolution: {integrity: sha512-Bq3SmSpyFHaWjPk8If9yc6svM8c56dB5BAtW4Qbw5jHTwwXXcTLoRMkpDJp6VL0XzlWaCHTXrkFURMYmD0sLqg==}
ansi-regex@6.3.0:
resolution: {integrity: sha512-WpDfL7NO6j7tH88IDBNVdUJxDh9nmCteAVW9dsep846XdwF4naCBK+/tGLX3KJgcpgMRXCFlTM2hKGoK9FsdrQ==}
engines: {node: '>=12'}
ansi-styles@4.3.0:
@@ -449,8 +454,8 @@ packages:
resolution: {integrity: sha512-nTjqfcBFEipKdXCv4YDQWCfmcLZKm81ldF0pAopTvyrFGVbcR6P/VAAd5G7N+0tTr8QqiU0tFadD6FK4NtJwOA==}
engines: {node: '>= 0.6'}
content-type@2.0.0:
resolution: {integrity: sha512-j/O/d7GcZCyNl7/hwZAb606rzqkyvaDctLmckbxLzHvFBzTJHuGEdodATcP3yIRoDrLHkIATJuvzbFlp/ki2cQ==}
content-type@2.1.0:
resolution: {integrity: sha512-mj7UPXE0jaqaOsukNZRUEfEi2AcL7C/vwmwcHV0O97eO1E1pxBZuyjlZrx5seTaNBg1U6+o35wpa35Qfcc+7ag==}
engines: {node: '>=18'}
conventional-changelog-angular@8.3.0:
@@ -475,8 +480,8 @@ packages:
resolution: {integrity: sha512-tQMagCOC59EVgNZcC5zl7XqO30Wki9i9J3acbUvkaosCT6JX3EeFwJD7Qqp4MCikRnzS18WXV3BLIQ66ytu6+Q==}
engines: {node: '>=18'}
conventional-commits-parser@6.3.0:
resolution: {integrity: sha512-RfOq/Cqy9xV9bOA8N+ZH6DlrDR+5S3Mi0B5kACEjESpE+AviIpAptx9a9cFpWCCvgRtWT+0BbUw+e1BZfts9jg==}
conventional-commits-parser@6.4.0:
resolution: {integrity: sha512-tvRg7FIBNlyPzjdG8wWRlPHQJJHI7DylhtRGeU9Lq+JuoPh5BKpPRX83ZdLrvXuOSu5Eo/e7SzOQhU4Hd2Miuw==}
engines: {node: '>=18'}
hasBin: true
@@ -584,14 +589,11 @@ packages:
escape-html@1.0.3:
resolution: {integrity: sha512-NiSupZ4OeuGwr68lGIeym/ksIZMJodUGOSCZ/FSnTxcrekbvqrgdUxlJOMpijaKZVjAJrWrGs/6Jy8OMuyj9ow==}
fast-content-type-parse@3.0.0:
resolution: {integrity: sha512-ZvLdcY8P+N8mGQJahJV5G4U88CSvT1rP8ApL6uETe88MBXrBHAkZlSEySdUlyztF7ccb+Znos3TFqaepHxdhBg==}
fast-deep-equal@3.1.3:
resolution: {integrity: sha512-f3qQ9oQy9j2AhBe/H9VC91wLmKBCCU/gDOnKNAYG5hswO7BLKj09Hc5HYNz9cGI++xlpDCIgDaitVs03ATR84Q==}
fast-uri@3.1.4:
resolution: {integrity: sha512-8JnbkQ4juDyvYs4mgFGQqg4yCYtFDtUtmp2QIQq11ZZe5CFQ5wcqm1rqDgAh/QdMySuBnPzMUiJUNZG5N/AiQw==}
fast-uri@3.1.5:
resolution: {integrity: sha512-gHwA1O9LDIcKunMKhObS/HimwtehO1nPUECKAu5TpKgaO19fcWEl4bliWe1jWxVFvIXztJjjQ4L8XQ1EU9f7Jw==}
fd-package-json@2.0.0:
resolution: {integrity: sha512-jKmm9YtsNXN789RS/0mSzOC1NUq9mkVd65vbSSVsKdjGvYXBuE4oWe2QOEoFeRmJg+lPuZxpmrfFclNhoRMneQ==}
@@ -639,8 +641,8 @@ packages:
resolution: {integrity: sha512-QLV1qeYSo5l13mQzWgP/y0LbMr5Plr5fJilgAIwgnwseproEbtNym8xpLsDzeZ6MWXgNE6kdWGBjdh3zT/Qerg==}
engines: {node: '>=20'}
handlebars@4.7.8:
resolution: {integrity: sha512-vafaFqs8MZkRrSX7sFVUdo3ap/eNiLnb4IakshzvP56X5Nr1iGKAIqdX6tMlm6HcNRIkr6AxO5jFEoJzzpT8aQ==}
handlebars@4.7.9:
resolution: {integrity: sha512-4E71E0rpOaQuJR2A3xDZ+GM1HyWYv1clR58tC8emQNeQe3RH7MAzSbat+V0wG78LQBo6m6bzSG/L4pBuCsgnUQ==}
engines: {node: '>=0.4.7'}
hasBin: true
@@ -648,8 +650,8 @@ packages:
resolution: {integrity: sha512-1cDNdwJ2Jaohmb3sg4OmKaMBwuC48sYni5HUw2DvsC8LjGTLK9h+eb1X6RyuOHe4hT0ULCW68iomhjUoKUqlPQ==}
engines: {node: '>= 0.4'}
hasown@2.0.3:
resolution: {integrity: sha512-ej4AhfhfL2Q2zpMmLo7U1Uv9+PyhIZpgQLGT1F9miIGmiCJIoCgSmczFdrc97mWT4kVY72KA+WnnhJ5pghSvSg==}
hasown@2.0.4:
resolution: {integrity: sha512-T2UbfbBEF32wiepXIsMlTW9+dDYC6wMh/t/vYA4tuOMKqWz/n3vr1NFSxQiyP+zk2mXsoMA/i/7qV6LKut1t1A==}
engines: {node: '>= 0.4'}
hermes-estree@0.34.0:
@@ -733,8 +735,8 @@ packages:
json-stringify-nice@1.1.4:
resolution: {integrity: sha512-5Z5RFW63yxReJ7vANgW6eZFGWaQvnPE3WNmZoOJrSkGju2etKA2L5rrOa1sm877TVTFt57A80BH1bArcmlLfPw==}
json-with-bigint@3.5.7:
resolution: {integrity: sha512-7ei3MdAI5+fJPVnKlW77TKNKwQ5ppSzWvhPuSuINT/GYW9ZOC1eRKOuhV9yHG5aEsUPj9BBx5JIekkmoLHxZOw==}
json-with-bigint@3.5.11:
resolution: {integrity: sha512-WvkM9Hfb9kqzCcbsvpwfWDvdfGZDhYuCoaCwHRe5q3LtULKkbrI/L6JYcN8owflgA3di5dP2yVAV2NVCXkgtkA==}
jsonata@2.1.0:
resolution: {integrity: sha512-OCzaRMK8HobtX8fp37uIVmL8CY1IGc/a6gLsDqz3quExFR09/U78HUzWYr7T31UEB6+Eu0/8dkVD5fFDOl9a8w==}
@@ -756,16 +758,16 @@ packages:
lru-cache@10.4.3:
resolution: {integrity: sha512-JNAzZcXrCt42VGLuYz0zfAzDfAvJWW6AfYlDBQyDV5DClI2m5sAmK+OIO7s59XfsRsWHp02jAJrRadPRGTt6SQ==}
lru-cache@11.2.7:
resolution: {integrity: sha512-aY/R+aEsRelme17KGQa/1ZSIpLpNYYrhcrepKTZgE+W3WM16YMCaPwOHLHsmopZHELU0Ojin1lPVxKR0MihncA==}
lru-cache@11.5.2:
resolution: {integrity: sha512-4pfM1Ff0x50o0tQwb5ucw/RzNyD0/YJME6IVcStalZuMWxdt3sR3huStTtxz4PUmvZfRguvDejasvQ2kifR11g==}
engines: {node: 20 || >=22}
math-intrinsics@1.1.0:
resolution: {integrity: sha512-/IXtbwEk5HTPyEwyKX6hGkYXxM9nbj64B+ilVJnC/R6B0pH5G4V3b0pVbL7DBj4tkhBAppbQUlf6F6Xl9LHu1g==}
engines: {node: '>= 0.4'}
media-typer@1.1.0:
resolution: {integrity: sha512-aisnrDP4GNe06UcKFnV5bfMNPBUw4jsLGaWwWfnH3v02GnBuXX2MCVn5RbrWo0j3pczUilYblq7fQ7Nw2t5XKw==}
media-typer@1.1.1:
resolution: {integrity: sha512-yz3xRaG20c6/BOzvYoDaGtPmGscs7YivItZEEqe6GbwNfHuxu9YNmvnEkMzKldAGY4/80pRcQRZSEnhquk9XuQ==}
engines: {node: '>= 0.8'}
meow@13.2.0:
@@ -903,8 +905,8 @@ packages:
resolution: {integrity: sha512-WPn+h9RGEExOKdu4bsF4HksG/uzd3cFq3MFtq8PsFeExPse5Ha/VOjQNyHhjboBFwGXGev6muJYTSPAOkROq2g==}
engines: {node: '>=18'}
qs@6.15.2:
resolution: {integrity: sha512-Rzq0KEyX/w/tEybncDgdkZrJgVUsUMk3xjh3t5bv3S1HTAtg+uOYt72+ZfwiQwKdysThkTBdL/rTi6HDmX9Ddw==}
qs@6.15.3:
resolution: {integrity: sha512-O9gl3zCl5h5blw1KGUzQKhA5oUXSl8rwUIM5o0S3nCXMliSvy5Dzx7/DJcI+SwgICv+IneSZwhBh1oSyEHA71A==}
engines: {node: '>=0.6'}
quick-lru@5.1.1:
@@ -944,8 +946,8 @@ packages:
safer-buffer@2.1.2:
resolution: {integrity: sha512-YZo3K82SD7Riyi0E1EQPojLz7kpepnSQI9IyPbHHg1XXXevb5dJI7tpyN2ADxGcQbHG7vcyRHk0cbwqcQriUtg==}
sax@1.6.0:
resolution: {integrity: sha512-6R3J5M4AcbtLUdZmRv2SygeVaM7IhrLXu9BmnOGmmACak8fiUtOsYNWUS4uK7upbmHIBbLBeFeI//477BKLBzA==}
sax@1.6.1:
resolution: {integrity: sha512-42tBVwLWnaQvW5zc4HbZrTuWccECCZfBi92FDuwtqxasH+JbPB3/FOKb1m222K42R4WxuxzzMsTswfzgtSu64Q==}
engines: {node: '>=11.0.0'}
semver@7.7.4:
@@ -973,8 +975,8 @@ packages:
resolution: {integrity: sha512-WPS/HvHQTYnHisLo9McqBHOJk2FkHO/tlpvldyrnem4aeQp4hai3gythswg6p01oSoTl58rcpiFAjF2br2Ak2A==}
engines: {node: '>= 0.4'}
side-channel@1.1.0:
resolution: {integrity: sha512-ZX99e6tRweoUXqR+VBrslhda51Nh5MTQwou5tnUDgbtyM0dBgmhEDtWGP/xbKn6hqfPRHujUNwz5fy/wbbhnpw==}
side-channel@1.1.1:
resolution: {integrity: sha512-6x6dK6zJdpTzF4sQeNYxwtvBzf6Eg4GtlesS94HOvTudUeyK2WXAaIfmDgsyslYrRBeFIlsi54AYsFGUuhmvrQ==}
engines: {node: '>= 0.4'}
signal-exit@4.1.0:
@@ -1070,12 +1072,12 @@ packages:
engines: {node: '>=0.8.0'}
hasBin: true
undici@6.24.1:
resolution: {integrity: sha512-sC+b0tB1whOCzbtlx20fx3WgCXwkW627p4EA9uM+/tNNPkSS+eSEld6pAs9nDv7WbY1UUljBMYPtu9BCOrCWKA==}
undici@6.28.0:
resolution: {integrity: sha512-LIY910g9TI13YS95lrMFrs8Rm/u/irgHeTWoKCoteeJ04CUJ92eEfj0rVn+7VKMPBpUPiUoBKfhNyLI23EE/KA==}
engines: {node: '>=18.17'}
undici@7.26.0:
resolution: {integrity: sha512-3O9Tf67pGhgOv9jM35AbhkXAKi13f3oy3aE4CSgr+TckGeY+/iu97ZXN+J7DpHPzLbVApFd1IFhcnBjREYXYcg==}
undici@7.29.0:
resolution: {integrity: sha512-IDxfleLmmbSskfWSUATiN1nfn2rDuvnMOqb5CWR92iIfojA0Ud+ulOAAEQ57LPr9rWmsreUyf5lwyao+7GNNVw==}
engines: {node: '>=20.18.1'}
universal-user-agent@7.0.3:
@@ -1149,13 +1151,13 @@ packages:
resolution: {integrity: sha512-YgvUTfwqyc7UXVMrB+SImsVYSmTS8X/tSrtdNZMImM+n7+QTriRXyXim0mBrTXNeqzVF0KWGgHPeiyViFFrNDw==}
engines: {node: '>=18'}
yaml@2.8.3:
resolution: {integrity: sha512-AvbaCLOO2Otw/lW5bmh9d/WEdcDFdQp2Z2ZUH3pX9U2ihyUY0nvLv7J6TrWowklRGPYbB/IuIMfYgxaCPg5Bpg==}
yaml@2.8.4:
resolution: {integrity: sha512-ml/JPOj9fOQK8RNnWojA67GbZ0ApXAUlN2UQclwv2eVgTgn7O9gg9o7paZWKMp4g0H3nTLtS9LVzhkpOFIKzog==}
engines: {node: '>= 14.6'}
hasBin: true
yaml@2.8.4:
resolution: {integrity: sha512-ml/JPOj9fOQK8RNnWojA67GbZ0ApXAUlN2UQclwv2eVgTgn7O9gg9o7paZWKMp4g0H3nTLtS9LVzhkpOFIKzog==}
yaml@2.9.0:
resolution: {integrity: sha512-2AvhNX3mb8zd6Zy7INTtSpl1F15HW6Wnqj0srWlkKLcpYl/gMIMJiyuGq2KeI2YFxUPjdlB+3Lc10seMLtL4cA==}
engines: {node: '>= 14.6'}
hasBin: true
@@ -1167,8 +1169,8 @@ packages:
resolution: {integrity: sha512-rwu/ClNdSMpkSrUb+d6BRsSkLUq1fmfsY6TOpYzTwvwkg1/NRG85KBy3kq++A8LKQwX6lsu+aWad+2khvuXrqw==}
engines: {node: ^20.19.0 || ^22.12.0 || >=23}
yargs@17.7.2:
resolution: {integrity: sha512-7dSzzRQ++CKnNI/krKnYRV7JKKPUXMEh61soaHKg9mrWEhzFWhFnxPxGl+69cD1Ou63C13NUPCnmIcrvqCuM6w==}
yargs@17.7.3:
resolution: {integrity: sha512-GZtjxm/J/4TSxuL3FNYjCmLktBTnIw/rVmKSIyKeYAZpmJB2ig9VauCC5xsa82GNKVKDAqpOn3KVzNt0zmrU0g==}
engines: {node: '>=12'}
yargs@18.0.0:
@@ -1187,14 +1189,14 @@ snapshots:
'@octokit/core': 7.0.6
'@octokit/plugin-paginate-rest': 14.0.0(@octokit/core@7.0.6)
'@octokit/plugin-rest-endpoint-methods': 17.0.0(@octokit/core@7.0.6)
'@octokit/request': 10.0.8
'@octokit/request-error': 7.1.0
undici: 6.24.1
'@octokit/request': 10.0.13
'@octokit/request-error': 7.1.1
undici: 6.28.0
'@actions/http-client@3.0.2':
dependencies:
tunnel: 0.0.6
undici: 6.24.1
undici: 6.28.0
'@appthreat/atom-common@1.1.0':
optional: true
@@ -1205,7 +1207,7 @@ snapshots:
'@babel/parser': 7.29.3
hermes-parser: 0.34.0
typescript: 6.0.3
yargs: 17.7.2
yargs: 17.7.3
optional: true
'@appthreat/atom@2.5.2':
@@ -1224,10 +1226,10 @@ snapshots:
js-tokens: 4.0.0
picocolors: 1.1.1
'@babel/generator@7.29.7':
'@babel/generator@7.29.8':
dependencies:
'@babel/parser': 7.29.7
'@babel/types': 7.29.7
'@babel/parser': 7.29.8
'@babel/types': 7.29.8
'@jridgewell/gen-mapping': 0.3.13
'@jridgewell/trace-mapping': 0.3.31
jsesc: 3.1.0
@@ -1240,31 +1242,31 @@ snapshots:
'@babel/parser@7.29.3':
dependencies:
'@babel/types': 7.29.7
'@babel/types': 7.29.8
'@babel/parser@7.29.7':
'@babel/parser@7.29.8':
dependencies:
'@babel/types': 7.29.7
'@babel/types': 7.29.8
'@babel/template@7.29.7':
dependencies:
'@babel/code-frame': 7.29.7
'@babel/parser': 7.29.7
'@babel/types': 7.29.7
'@babel/parser': 7.29.8
'@babel/types': 7.29.8
'@babel/traverse@7.29.0':
dependencies:
'@babel/code-frame': 7.29.7
'@babel/generator': 7.29.7
'@babel/generator': 7.29.8
'@babel/helper-globals': 7.29.7
'@babel/parser': 7.29.3
'@babel/template': 7.29.7
'@babel/types': 7.29.7
'@babel/types': 7.29.8
debug: 4.4.3
transitivePeerDependencies:
- supports-color
'@babel/types@7.29.7':
'@babel/types@7.29.8':
dependencies:
'@babel/helper-string-parser': 7.29.7
'@babel/helper-validator-identifier': 7.29.7
@@ -1308,14 +1310,14 @@ snapshots:
'@cdxgen/cdxgen-plugins-bin@2.1.1':
optional: true
'@conventional-changelog/git-client@2.6.0(conventional-commits-filter@5.0.0)(conventional-commits-parser@6.3.0)':
'@conventional-changelog/git-client@2.7.0(conventional-commits-filter@5.0.0)(conventional-commits-parser@6.4.0)':
dependencies:
'@simple-libs/child-process-utils': 1.0.2
'@simple-libs/stream-utils': 1.2.0
semver: 7.7.4
optionalDependencies:
conventional-commits-filter: 5.0.0
conventional-commits-parser: 6.3.0
conventional-commits-parser: 6.4.0
'@cyclonedx/cdxgen@12.4.0':
dependencies:
@@ -1420,7 +1422,7 @@ snapshots:
'@gar/promise-retry': 1.0.3
'@npmcli/promise-spawn': 9.0.1
ini: 6.0.0
lru-cache: 11.2.7
lru-cache: 11.5.2
npm-pick-manifest: 11.0.3
proc-log: 6.1.0
semver: 7.7.4
@@ -1454,26 +1456,28 @@ snapshots:
'@octokit/core@7.0.6':
dependencies:
'@octokit/auth-token': 6.0.0
'@octokit/graphql': 9.0.3
'@octokit/request': 10.0.8
'@octokit/request-error': 7.1.0
'@octokit/graphql': 9.0.4
'@octokit/request': 10.0.13
'@octokit/request-error': 7.1.1
'@octokit/types': 16.0.0
before-after-hook: 4.0.0
universal-user-agent: 7.0.3
'@octokit/endpoint@11.0.3':
'@octokit/endpoint@11.0.4':
dependencies:
'@octokit/types': 16.0.0
'@octokit/types': 17.0.0
universal-user-agent: 7.0.3
'@octokit/graphql@9.0.3':
'@octokit/graphql@9.0.4':
dependencies:
'@octokit/request': 10.0.8
'@octokit/types': 16.0.0
'@octokit/request': 10.0.13
'@octokit/types': 17.0.0
universal-user-agent: 7.0.3
'@octokit/openapi-types@27.0.0': {}
'@octokit/openapi-types@28.0.0': {}
'@octokit/plugin-paginate-rest@14.0.0(@octokit/core@7.0.6)':
dependencies:
'@octokit/core': 7.0.6
@@ -1484,23 +1488,27 @@ snapshots:
'@octokit/core': 7.0.6
'@octokit/types': 16.0.0
'@octokit/request-error@7.1.0':
'@octokit/request-error@7.1.1':
dependencies:
'@octokit/types': 16.0.0
'@octokit/types': 17.0.0
'@octokit/request@10.0.8':
'@octokit/request@10.0.13':
dependencies:
'@octokit/endpoint': 11.0.3
'@octokit/request-error': 7.1.0
'@octokit/types': 16.0.0
fast-content-type-parse: 3.0.0
json-with-bigint: 3.5.7
'@octokit/endpoint': 11.0.4
'@octokit/request-error': 7.1.1
'@octokit/types': 17.0.0
content-type: 2.1.0
json-with-bigint: 3.5.11
universal-user-agent: 7.0.3
'@octokit/types@16.0.0':
dependencies:
'@octokit/openapi-types': 27.0.0
'@octokit/types@17.0.0':
dependencies:
'@octokit/openapi-types': 28.0.0
'@sec-ant/readable-stream@0.4.1': {}
'@simple-libs/child-process-utils@1.0.2':
@@ -1524,14 +1532,14 @@ snapshots:
ajv@8.20.0:
dependencies:
fast-deep-equal: 3.1.3
fast-uri: 3.1.4
fast-uri: 3.1.5
json-schema-traverse: 1.0.0
require-from-string: 2.0.2
ansi-regex@5.0.1:
optional: true
ansi-regex@6.2.2: {}
ansi-regex@6.3.0: {}
ansi-styles@4.3.0:
dependencies:
@@ -1562,7 +1570,7 @@ snapshots:
http-errors: 2.0.1
iconv-lite: 0.7.2
on-finished: 2.4.1
qs: 6.15.2
qs: 6.15.3
raw-body: 3.0.2
type-is: 2.1.0
transitivePeerDependencies:
@@ -1624,7 +1632,7 @@ snapshots:
parse5: 7.3.0
parse5-htmlparser2-tree-adapter: 7.1.0
parse5-parser-stream: 7.1.2
undici: 7.26.0
undici: 7.29.0
whatwg-mimetype: 4.0.0
chownr@3.0.0: {}
@@ -1690,8 +1698,7 @@ snapshots:
content-type@1.0.5:
optional: true
content-type@2.0.0:
optional: true
content-type@2.1.0: {}
conventional-changelog-angular@8.3.0:
dependencies:
@@ -1703,18 +1710,18 @@ snapshots:
dependencies:
'@simple-libs/stream-utils': 1.2.0
conventional-commits-filter: 5.0.0
handlebars: 4.7.8
handlebars: 4.7.9
meow: 13.2.0
semver: 7.7.4
conventional-changelog@7.2.0(conventional-commits-filter@5.0.0):
dependencies:
'@conventional-changelog/git-client': 2.6.0(conventional-commits-filter@5.0.0)(conventional-commits-parser@6.3.0)
'@conventional-changelog/git-client': 2.7.0(conventional-commits-filter@5.0.0)(conventional-commits-parser@6.4.0)
'@simple-libs/hosted-git-info': 1.0.2
'@types/normalize-package-data': 2.4.4
conventional-changelog-preset-loader: 5.0.0
conventional-changelog-writer: 8.4.0
conventional-commits-parser: 6.3.0
conventional-commits-parser: 6.4.0
fd-package-json: 2.0.0
meow: 13.2.0
normalize-package-data: 7.0.1
@@ -1723,7 +1730,7 @@ snapshots:
conventional-commits-filter@5.0.0: {}
conventional-commits-parser@6.3.0:
conventional-commits-parser@6.4.0:
dependencies:
'@simple-libs/stream-utils': 1.2.0
meow: 13.2.0
@@ -1823,11 +1830,9 @@ snapshots:
escape-html@1.0.3:
optional: true
fast-content-type-parse@3.0.0: {}
fast-deep-equal@3.1.3: {}
fast-uri@3.1.4: {}
fast-uri@3.1.5: {}
fd-package-json@2.0.0:
dependencies:
@@ -1865,7 +1870,7 @@ snapshots:
get-proto: 1.0.1
gopd: 1.2.0
has-symbols: 1.1.0
hasown: 2.0.3
hasown: 2.0.4
math-intrinsics: 1.1.0
optional: true
@@ -1904,7 +1909,7 @@ snapshots:
responselike: 4.0.2
type-fest: 4.41.0
handlebars@4.7.8:
handlebars@4.7.9:
dependencies:
minimist: 1.2.8
neo-async: 2.6.2
@@ -1916,7 +1921,7 @@ snapshots:
has-symbols@1.1.0:
optional: true
hasown@2.0.3:
hasown@2.0.4:
dependencies:
function-bind: 1.1.2
optional: true
@@ -1935,7 +1940,7 @@ snapshots:
hosted-git-info@9.0.3:
dependencies:
lru-cache: 11.2.7
lru-cache: 11.5.2
htmlparser2@10.1.0:
dependencies:
@@ -1994,7 +1999,7 @@ snapshots:
json-stringify-nice@1.1.4: {}
json-with-bigint@3.5.7: {}
json-with-bigint@3.5.11: {}
jsonata@2.1.0:
optional: true
@@ -2011,12 +2016,12 @@ snapshots:
lru-cache@10.4.3: {}
lru-cache@11.2.7: {}
lru-cache@11.5.2: {}
math-intrinsics@1.1.0:
optional: true
media-typer@1.1.0:
media-typer@1.1.1:
optional: true
meow@13.2.0: {}
@@ -2133,7 +2138,7 @@ snapshots:
path-scurry@2.0.2:
dependencies:
lru-cache: 11.2.7
lru-cache: 11.5.2
minipass: 7.1.3
picocolors@1.1.1: {}
@@ -2147,9 +2152,10 @@ snapshots:
transitivePeerDependencies:
- supports-color
qs@6.15.2:
qs@6.15.3:
dependencies:
side-channel: 1.1.0
es-define-property: 1.0.1
side-channel: 1.1.1
optional: true
quick-lru@5.1.1: {}
@@ -2185,7 +2191,7 @@ snapshots:
safer-buffer@2.1.2: {}
sax@1.6.0: {}
sax@1.6.1: {}
semver@7.7.4: {}
@@ -2217,7 +2223,7 @@ snapshots:
side-channel-map: 1.0.1
optional: true
side-channel@1.1.0:
side-channel@1.1.1:
dependencies:
es-errors: 1.3.0
object-inspect: 1.13.4
@@ -2279,7 +2285,7 @@ snapshots:
strip-ansi@7.2.0:
dependencies:
ansi-regex: 6.2.2
ansi-regex: 6.3.0
tar@7.5.15:
dependencies:
@@ -2307,8 +2313,8 @@ snapshots:
type-is@2.1.0:
dependencies:
content-type: 2.0.0
media-typer: 1.1.0
content-type: 2.1.0
media-typer: 1.1.1
mime-types: 3.0.2
optional: true
@@ -2318,9 +2324,9 @@ snapshots:
uglify-js@3.19.3:
optional: true
undici@6.24.1: {}
undici@6.28.0: {}
undici@7.26.0: {}
undici@7.29.0: {}
universal-user-agent@7.0.3: {}
@@ -2375,22 +2381,22 @@ snapshots:
xml-js@1.6.11:
dependencies:
sax: 1.6.0
sax: 1.6.1
y18n@5.0.8: {}
yallist@5.0.0: {}
yaml@2.8.3: {}
yaml@2.8.4: {}
yaml@2.9.0: {}
yargs-parser@21.1.1:
optional: true
yargs-parser@22.0.0: {}
yargs@17.7.2:
yargs@17.7.3:
dependencies:
cliui: 8.0.1
escalade: 3.2.0
-12
View File
@@ -1,13 +1 @@
audit = false
fund = false
update-notifier = false
auto-install-peers = true
strict-peer-dependencies = false
prefer-workspace-packages = true
link-workspace-packages = deep
hoist = true
hoist-workspace-packages = false
loglevel = warn
package-manager-strict=false
# https://github.com/pnpm/pnpm/issues/7024
package-import-method=clone-or-copy
+8 -9
View File
@@ -1,5 +1,5 @@
ARG NODE_VERSION=26.5.1
ARG PNPM_VERSION=10.32.1
ARG PNPM_VERSION=11.22.0
ARG PYTHON_VERSION=3.13
# ==============================================================================
@@ -11,13 +11,7 @@ COPY ./dist/task-runner-javascript /app/task-runner-javascript
WORKDIR /app/task-runner-javascript
# Pin pnpm to the repo's packageManager version. `pnpm deploy` drops the
# packageManager field from the deployed package.json, so nothing else here pins it,
# and pnpm 11.x defaults minimumReleaseAge to 1440 (24h), which would make the
# `pnpm add` below reject any dependency published less than a day ago — e.g. a
# first-party @n8n_io/ai-assistant-sdk bump landed within hours of its npm publish.
# This container step only re-resolves an already-vetted, already-pinned dependency
# set; the real supply-chain age policy is enforced by the host install
# (pnpm-workspace.yaml + SafeChain).
# packageManager field from the deployed package.json, so nothing else here pins it.
ARG PNPM_VERSION
RUN npm i -g "pnpm@${PNPM_VERSION}"
@@ -36,9 +30,14 @@ RUN node -e "const pkg = require('./package.json'); \
delete pkg.devDependencies; \
require('fs').writeFileSync('./package.json', JSON.stringify(pkg, null, 2));"
# `--config.minimum-release-age=0`: pnpm 11 defaults it to 1440 (24h), which would make
# this reject any dependency published less than a day ago — e.g. a first-party
# @n8n_io/ai-assistant-sdk bump landed within hours of its npm publish. This step only
# re-resolves an already-vetted, already-pinned dependency set; the real supply-chain age
# policy is enforced by the host install (pnpm-workspace.yaml + SafeChain).
# Install moment (special case for backwards compatibility)
RUN rm -f node_modules/.modules.yaml && \
pnpm add moment@2.30.1 --prod --no-lockfile
pnpm add moment@2.30.1 --prod --no-lockfile --config.minimum-release-age=0
# ==============================================================================
# STAGE 2: Python runner build (@n8n/task-runner-python) with uv
+8 -9
View File
@@ -13,7 +13,7 @@
# ==============================================================================
ARG NODE_VERSION=26.5.1
ARG PNPM_VERSION=10.32.1
ARG PNPM_VERSION=11.22.0
ARG PYTHON_VERSION=3.13
@@ -26,13 +26,7 @@ COPY ./dist/task-runner-javascript /app/task-runner-javascript
WORKDIR /app/task-runner-javascript
# Pin pnpm to the repo's packageManager version. `pnpm deploy` drops the
# packageManager field from the deployed package.json, so nothing else here pins it,
# and pnpm 11.x defaults minimumReleaseAge to 1440 (24h), which would make the
# `pnpm add` below reject any dependency published less than a day ago — e.g. a
# first-party @n8n_io/ai-assistant-sdk bump landed within hours of its npm publish.
# This container step only re-resolves an already-vetted, already-pinned dependency
# set; the real supply-chain age policy is enforced by the host install
# (pnpm-workspace.yaml + SafeChain).
# packageManager field from the deployed package.json, so nothing else here pins it.
ARG PNPM_VERSION
RUN npm i -g "pnpm@${PNPM_VERSION}"
@@ -51,9 +45,14 @@ RUN node -e "const pkg = require('./package.json'); \
delete pkg.devDependencies; \
require('fs').writeFileSync('./package.json', JSON.stringify(pkg, null, 2));"
# `--config.minimum-release-age=0`: pnpm 11 defaults it to 1440 (24h), which would make
# this reject any dependency published less than a day ago — e.g. a first-party
# @n8n_io/ai-assistant-sdk bump landed within hours of its npm publish. This step only
# re-resolves an already-vetted, already-pinned dependency set; the real supply-chain age
# policy is enforced by the host install (pnpm-workspace.yaml + SafeChain).
# Install moment by default (special case for n8n cloud)
RUN rm -f node_modules/.modules.yaml && \
pnpm add moment@2.30.1 --prod --no-lockfile
pnpm add moment@2.30.1 --prod --no-lockfile --config.minimum-release-age=0
# Rebuild isolated-vm for the container platform. Install build tools as
# fallback in case prebuild-install cannot find a prebuilt binary.
-7
View File
@@ -32,13 +32,6 @@ pre-commit:
skip:
- merge
- rebase
# Supersedes the zod-only peer check: same guard, generalized to every curated library.
single_instance_libs_check:
glob: '**/package.json'
run: pnpm --dir packages/testing/code-health exec tsx src/cli.ts --rule=single-instance-libs
skip:
- merge
- rebase
workspace_private_deps_check:
glob: '**/package.json'
run: node scripts/check-workspace-private-deps.mjs
+2 -147
View File
@@ -4,9 +4,9 @@
"private": true,
"engines": {
"node": ">=24.0.0",
"pnpm": ">=10.22.0"
"pnpm": ">=11.22.0"
},
"packageManager": "pnpm@10.32.1",
"packageManager": "pnpm@11.22.0",
"scripts": {
"prepare": "node scripts/prepare.mjs",
"preinstall": "node scripts/block-npm-install.js",
@@ -104,150 +104,5 @@
"typescript": "6.0.2",
"yaml": "catalog:",
"zx": "^8.8.5"
},
"pnpm": {
"onlyBuiltDependencies": [
"@confluentinc/kafka-javascript",
"@vscode/ripgrep",
"isolated-vm",
"sqlite3"
],
"overrides": {
"libphonenumber-js": "npm:empty-npm-package@1.0.0",
"@browserbasehq/stagehand": "npm:empty-npm-package@1.0.0",
"sharp": "npm:empty-npm-package@1.0.0",
"ast-types": "0.16.1",
"baseline-browser-mapping": "^2.10.31",
"@azure/identity": "4.13.0",
"@lezer/common": "^1.2.0",
"@mistralai/mistralai": "^1.10.0",
"@n8n/typeorm>@sentry/node": "catalog:sentry",
"@opentelemetry/api": "catalog:",
"@opentelemetry/core": "2.10.0",
"@opentelemetry/propagator-jaeger": "2.10.0",
"@types/node": "^20.17.50",
"chokidar": "4.0.3",
"esbuild": "catalog:",
"multer": "^2.2.0",
"prebuild-install": "7.1.3",
"pug": "^3.0.3",
"semver": "catalog:",
"tar-fs": "2.1.5",
"tslib": "^2.6.2",
"tsconfig-paths": "^4.2.0",
"vue-tsc": "catalog:frontend",
"gaxios": ">=7.1.1",
"google-gax": "^4.3.7",
"ws": ">=8.21.1",
"date-fns": "2.30.0",
"date-fns-tz": "2.0.0",
"form-data": "4.0.6",
"pdf-parse": "catalog:",
"pdfjs-dist": "catalog:",
"tmp": "0.2.7",
"nodemailer": "8.0.10",
"validator": "13.15.26",
"zod": "3.25.76",
"js-yaml": "4.3.1",
"katex": "0.18.2",
"body-parser": "2.3.0",
"glob@10": "10.5.0",
"glob@7": "7.2.3",
"jws@3": "3.2.2",
"jws@4": "4.0.1",
"qs": "catalog:",
"@smithy/config-resolver": ">=4.4.0",
"@rudderstack/rudder-sdk-node@<=3.0.0": "3.0.0",
"diff": "8.0.3",
"tar": "catalog:",
"ajv@6": "6.15.0",
"ajv@7": "8.20.0",
"ajv@8": "8.20.0",
"bn.js@4": "5.2.3",
"bn.js@5": "5.2.3",
"lodash": "4.18.1",
"minimatch@<=5.1.8": "5.1.8",
"minimatch@10": "10.2.3",
"@hono/node-server": "1.19.15",
"follow-redirects": "1.16.0",
"express-rate-limit": "8.2.2",
"underscore": "1.13.8",
"flatted": "3.4.2",
"handlebars": "4.7.9",
"path-to-regexp": "8.4.0",
"path-to-regexp@<0.1.13": "0.1.13",
"picomatch@2": "2.3.2",
"picomatch@4": "4.0.4",
"avsc": "5.7.9",
"brace-expansion@<2.1.4": "2.1.4",
"@xmldom/xmldom": "0.8.14",
"yaml@<=2.8.3": "2.8.3",
"axios": "catalog:",
"fast-xml-builder": "1.2.1",
"fast-xml-parser": "5.7.2",
"postcss@<=8.5.22": "8.5.23",
"@anthropic-ai/sdk@<=0.91.1": "0.91.1",
"uuid@<=13.0.1": "13.0.1",
"fast-uri": "3.1.5",
"cjs-module-lexer@<2.2.0": "2.2.0",
"protobufjs": "7.6.5",
"shell-quote": "1.9.0",
"adm-zip": "0.6.0",
"ip-address@10": "10.3.1",
"brace-expansion@5": "5.0.9",
"@tootallnate/once@2": "2.0.1",
"@vue/server-renderer@3.5.26": "3.5.40",
"@vue/shared@3.5.26": "3.5.40",
"@opentelemetry/exporter-prometheus@<=0.217.0": "0.217.0",
"@opentelemetry/sdk-node@<=0.217.0": "0.217.0",
"@daytona/sdk@0.194.0>@aws-sdk/client-s3": "3.808.0",
"@daytona/sdk@0.194.0>@aws-sdk/lib-storage": "3.808.0",
"@daytona/sdk@0.194.0>@opentelemetry/sdk-trace-base": "2.7.1",
"langsmith": "0.6.0",
"hono": "4.12.34",
"@tiptap/core": "catalog:",
"pg": "catalog:",
"file-type": "catalog:",
"linkify-it@<=5.0.1": "5.0.2",
"highlight.js@11": "catalog:frontend",
"jose@<6.2.9": "6.2.9",
"node-rsa": "2.0.0",
"@turbo/darwin-64@<=2.9.18": "2.9.18",
"@turbo/linux-64@<=2.9.18": "2.9.18",
"@turbo/windows-64@<=2.9.18": "2.9.18",
"ibm-cloud-sdk-core": "^5.5.0",
"undici@5": "catalog:undici-v6",
"undici@6": "catalog:undici-v6",
"undici@7": "catalog:undici-v7",
"node-gyp>undici": "catalog:undici-v7",
"@babel/traverse": "^7.23.2",
"@vitest/browser@<4.1.10": "4.1.10",
"immutable": "5.1.8",
"nanoid@<3.3.18": "catalog:",
"@zone-eu/mailsplit@<5.4.15": "5.4.15",
"strnum@<2.4.2": "2.4.2"
},
"patchedDependencies": {
"axios": "patches/axios.patch",
"bull@4.16.4": "patches/bull@4.16.4.patch",
"pdfjs-dist@5.4.296": "patches/pdfjs-dist@5.4.296.patch",
"pkce-challenge@5.0.0": "patches/pkce-challenge@5.0.0.patch",
"@types/express-serve-static-core@5.0.6": "patches/@types__express-serve-static-core@5.0.6.patch",
"@types/ws@8.18.1": "patches/@types__ws@8.18.1.patch",
"vue-tsc@2.2.8": "patches/vue-tsc@2.2.8.patch",
"element-plus@2.4.3": "patches/element-plus@2.4.3.patch",
"ics": "patches/ics.patch",
"minifaker": "patches/minifaker.patch",
"z-vue-scan": "patches/z-vue-scan.patch",
"@lezer/highlight": "patches/@lezer__highlight.patch",
"v-code-diff": "patches/v-code-diff.patch",
"vuedraggable@4.1.0": "patches/vuedraggable@4.1.0.patch",
"assert@2.1.0": "patches/assert@2.1.0.patch",
"reka-ui@2.5.0": "patches/reka-ui@2.5.0.patch",
"lodash@4.18.1": "patches/lodash@4.18.1.patch",
"@langchain/openai@1.4.4": "patches/@langchain__openai@1.4.4.patch",
"@langchain/google-common@2.1.24": "patches/@langchain__google-common@2.1.24.patch",
"@confluentinc/kafka-javascript@1.9.1": "patches/@confluentinc__kafka-javascript@1.9.1.patch"
}
}
}
+3 -3
View File
@@ -33,9 +33,10 @@
"clean": "rimraf dist",
"dev": "tsdown --watch",
"lint": "eslint . --quiet",
"typecheck:frontend": "vue-tsc --noEmit --project tsconfig.frontend.json",
"typecheck": "pnpm --sequential run \"/^typecheck:.+/\"",
"typecheck:frontend": "tsc --noEmit --project tsconfig.frontend.json",
"typecheck:backend": "tsc --noEmit --project tsconfig.backend.json",
"build": "pnpm \"/^typecheck:.+/\" && pnpm clean && tsdown && pnpm create-json-schema",
"build": "pnpm typecheck && pnpm clean && tsdown && pnpm create-json-schema",
"build:unchecked": "pnpm run build",
"create-json-schema": "tsx scripts/create-json-schema.ts",
"preview": "vite preview",
@@ -57,7 +58,6 @@
"vite": "catalog:",
"vue": "catalog:frontend",
"vue-router": "catalog:frontend",
"vue-tsc": "catalog:frontend",
"zod-to-json-schema": "catalog:",
"tsx": "catalog:"
},
@@ -71,7 +71,7 @@
"@vitejs/plugin-vue": "catalog:frontend",
"@vitest/coverage-v8": "catalog:",
"@vue/test-utils": "catalog:frontend",
"autoprefixer": "^10.4.19",
"autoprefixer": "catalog:frontend",
"emojibase-data": "^17.0.0",
"eslint-plugin-storybook": "catalog:storybook",
"pinia": "catalog:frontend",
+1
View File
@@ -164,6 +164,7 @@
"@vitejs/plugin-vue": "catalog:frontend",
"@vitest/coverage-v8": "catalog:",
"@vue/test-utils": "catalog:frontend",
"autoprefixer": "catalog:frontend",
"browserslist": "4.28.1",
"browserslist-to-esbuild": "^2.1.1",
"eslint-plugin-oxlint": "catalog:",
@@ -21,10 +21,16 @@ interface PackageOpts {
overrides?: Record<string, string>;
}
function writeRootPackageJson(dir: string, opts: PackageOpts = {}): void {
const body: Record<string, unknown> = { name: 'root', private: true };
if (opts.overrides) body.pnpm = { overrides: opts.overrides };
writeFile(dir, 'package.json', JSON.stringify(body, null, 2));
/** Appends an `overrides:` block to the workspace manifest written by {@link writeWorkspace}. */
function writeOverrides(dir: string, opts: PackageOpts = {}): void {
if (!opts.overrides) return;
const lines = ['overrides:'];
for (const [key, target] of Object.entries(opts.overrides)) {
lines.push(` ${quoteIfNeeded(key)}: ${quoteIfNeeded(target)}`);
}
const workspacePath = path.join(dir, 'pnpm-workspace.yaml');
const existing = fs.existsSync(workspacePath) ? fs.readFileSync(workspacePath, 'utf-8') : '';
fs.writeFileSync(workspacePath, `${existing}${lines.join('\n')}\n`);
}
function writeWorkspace(dir: string, body: string): void {
@@ -109,7 +115,7 @@ describe('StaleOverridesRule', () => {
it('flags override that duplicates a catalog entry', () => {
writeWorkspace(tmpDir, 'packages:\n - packages/*\ncatalog:\n lodash: 4.18.1\n');
writeRootPackageJson(tmpDir, { overrides: { lodash: '4.18.1' } });
writeOverrides(tmpDir, { overrides: { lodash: '4.18.1' } });
writeLock(tmpDir, { packages: ['lodash@4.18.1'] });
const violations = rule.analyze(context());
@@ -124,7 +130,7 @@ describe('StaleOverridesRule', () => {
tmpDir,
'packages:\n - packages/*\ncatalogs:\n sentry:\n "@sentry/node": ^10.0.0\n',
);
writeRootPackageJson(tmpDir, { overrides: { '@sentry/node': '^10.0.0' } });
writeOverrides(tmpDir, { overrides: { '@sentry/node': '^10.0.0' } });
writeLock(tmpDir, { packages: ['@sentry/node@10.0.0'] });
const violations = rule.analyze(context());
@@ -136,7 +142,7 @@ describe('StaleOverridesRule', () => {
it('does not flag overrides whose target is already a catalog reference', () => {
writeWorkspace(tmpDir, 'packages:\n - packages/*\ncatalog:\n typescript: 5.9.2\n');
writeRootPackageJson(tmpDir, { overrides: { typescript: 'catalog:' } });
writeOverrides(tmpDir, { overrides: { typescript: 'catalog:' } });
writeLock(tmpDir, { packages: ['typescript@5.9.2'] });
const violations = rule.analyze(context());
@@ -146,7 +152,7 @@ describe('StaleOverridesRule', () => {
it('flags orphan override when package is absent from lockfile', () => {
writeWorkspace(tmpDir, 'packages:\n - packages/*\ncatalog: {}\n');
writeRootPackageJson(tmpDir, { overrides: { 'gone-from-graph': '1.0.0' } });
writeOverrides(tmpDir, { overrides: { 'gone-from-graph': '1.0.0' } });
writeLock(tmpDir, { packages: ['something-else@1.0.0'] });
const violations = rule.analyze(context());
@@ -158,7 +164,7 @@ describe('StaleOverridesRule', () => {
it('does not flag empty-npm-package substitutions as orphans', () => {
writeWorkspace(tmpDir, 'packages:\n - packages/*\ncatalog: {}\n');
writeRootPackageJson(tmpDir, {
writeOverrides(tmpDir, {
overrides: { sharp: 'npm:empty-npm-package@1.0.0' },
});
writeLock(tmpDir, { packages: ['something-else@1.0.0'] });
@@ -170,7 +176,7 @@ describe('StaleOverridesRule', () => {
it('parses descendant override keys and flags when parent is missing', () => {
writeWorkspace(tmpDir, 'packages:\n - packages/*\ncatalog: {}\n');
writeRootPackageJson(tmpDir, {
writeOverrides(tmpDir, {
overrides: { 'missing-parent>@sentry/node': '10.0.0' },
});
writeLock(tmpDir, { packages: ['@sentry/node@10.0.0'] });
@@ -183,7 +189,7 @@ describe('StaleOverridesRule', () => {
it('does not flag descendant override when parent is present', () => {
writeWorkspace(tmpDir, 'packages:\n - packages/*\ncatalog: {}\n');
writeRootPackageJson(tmpDir, {
writeOverrides(tmpDir, {
overrides: { '@n8n/typeorm>@sentry/node': '10.0.0' },
});
writeLock(tmpDir, {
@@ -197,7 +203,7 @@ describe('StaleOverridesRule', () => {
it('parses bracketed selector keys without flagging them as orphans', () => {
writeWorkspace(tmpDir, 'packages:\n - packages/*\ncatalog: {}\n');
writeRootPackageJson(tmpDir, { overrides: { 'undici@5': '^6.24.0' } });
writeOverrides(tmpDir, { overrides: { 'undici@5': '^6.24.0' } });
writeLock(tmpDir, { packages: ['undici@6.24.0'] });
const violations = rule.analyze(context());
@@ -207,7 +213,7 @@ describe('StaleOverridesRule', () => {
it('flags redundant pin when every declared range in node_modules matches the pinned version', () => {
writeWorkspace(tmpDir, 'packages:\n - packages/*\ncatalog: {}\n');
writeRootPackageJson(tmpDir, { overrides: { chokidar: '4.0.3' } });
writeOverrides(tmpDir, { overrides: { chokidar: '4.0.3' } });
writeLock(tmpDir, {
packages: ['chokidar@4.0.3'],
requestedRanges: { chokidar: '4.0.3' },
@@ -222,7 +228,7 @@ describe('StaleOverridesRule', () => {
it('does not flag redundant pin when a transitive declares a wider range', () => {
writeWorkspace(tmpDir, 'packages:\n - packages/*\ncatalog: {}\n');
writeRootPackageJson(tmpDir, { overrides: { zod: '3.25.67' } });
writeOverrides(tmpDir, { overrides: { zod: '3.25.67' } });
writeLock(tmpDir, {
packages: ['zod@3.25.67'],
requestedRanges: { zod: '3.25.67' },
@@ -239,7 +245,7 @@ describe('StaleOverridesRule', () => {
it('does not flag redundant pin when node_modules is absent', () => {
writeWorkspace(tmpDir, 'packages:\n - packages/*\ncatalog: {}\n');
writeRootPackageJson(tmpDir, { overrides: { chokidar: '4.0.3' } });
writeOverrides(tmpDir, { overrides: { chokidar: '4.0.3' } });
writeLock(tmpDir, {
packages: ['chokidar@4.0.3'],
requestedRanges: { chokidar: '4.0.3' },
@@ -253,7 +259,7 @@ describe('StaleOverridesRule', () => {
it('does not flag redundant pin when range uses semver operator', () => {
writeWorkspace(tmpDir, 'packages:\n - packages/*\ncatalog: {}\n');
writeRootPackageJson(tmpDir, { overrides: { axios: '^1.16.0' } });
writeOverrides(tmpDir, { overrides: { axios: '^1.16.0' } });
writeLock(tmpDir, {
packages: ['axios@1.16.0'],
requestedRanges: { axios: '^1.16.0' },
@@ -268,7 +274,7 @@ describe('StaleOverridesRule', () => {
it('does not flag redundant pin when multiple versions are resolved', () => {
writeWorkspace(tmpDir, 'packages:\n - packages/*\ncatalog: {}\n');
writeRootPackageJson(tmpDir, { overrides: { 'shared-lib': '1.0.0' } });
writeOverrides(tmpDir, { overrides: { 'shared-lib': '1.0.0' } });
writeLock(tmpDir, {
packages: ['shared-lib@1.0.0', 'shared-lib@2.0.0'],
requestedRanges: { 'shared-lib': '1.0.0' },
@@ -283,7 +289,7 @@ describe('StaleOverridesRule', () => {
it('returns no violations when there are no overrides', () => {
writeWorkspace(tmpDir, 'packages:\n - packages/*\ncatalog: {}\n');
writeRootPackageJson(tmpDir, {});
writeOverrides(tmpDir, {});
writeLock(tmpDir, { packages: ['lodash@4.18.1'] });
const violations = rule.analyze(context());
@@ -299,7 +305,7 @@ describe('StaleOverridesRule', () => {
tmpDir,
'packages:\n - packages/*\ncatalogs:\n undici-v6:\n undici: ^6.27.0\n',
);
writeRootPackageJson(tmpDir, { overrides: { 'undici@<=6.27.0': '6.27.0' } });
writeOverrides(tmpDir, { overrides: { 'undici@<=6.27.0': '6.27.0' } });
writeLock(tmpDir, { packages: ['undici@6.27.0'] });
const violations = rule.analyze(context());
@@ -314,7 +320,7 @@ describe('StaleOverridesRule', () => {
// Regression: a dependency autofix pinned `@tiptap/core@<=3.27.0` to a
// concrete version while the default catalog already pins @tiptap/core.
writeWorkspace(tmpDir, "packages:\n - packages/*\ncatalog:\n '@tiptap/core': 3.22.5\n");
writeRootPackageJson(tmpDir, { overrides: { '@tiptap/core@<=3.27.0': '3.27.0' } });
writeOverrides(tmpDir, { overrides: { '@tiptap/core@<=3.27.0': '3.27.0' } });
writeLock(tmpDir, { packages: ['@tiptap/core@3.27.0'] });
const violations = rule.analyze(context());
@@ -346,7 +352,7 @@ describe('StaleOverridesRule', () => {
const hasCatalogDuplicate = (overrideKey: string, pkg: string): boolean => {
const workspace = `packages:\n - packages/*\ncatalog:\n '${pkg}': 1.0.0\n`;
writeWorkspace(tmpDir, workspace);
writeRootPackageJson(tmpDir, { overrides: { [overrideKey]: '1.0.0' } });
writeOverrides(tmpDir, { overrides: { [overrideKey]: '1.0.0' } });
writeLock(tmpDir, { packages: [`${pkg}@1.0.0`] });
return rule.analyze(context()).some((v) => v.message.includes('duplicates a catalog entry'));
};
@@ -362,9 +368,9 @@ describe('StaleOverridesRule', () => {
);
});
it('reports the line number of the override key in package.json', () => {
it('reports the line number of the override key in the workspace manifest', () => {
writeWorkspace(tmpDir, 'packages:\n - packages/*\ncatalog:\n lodash: 4.18.1\n');
writeRootPackageJson(tmpDir, { overrides: { lodash: '4.18.1' } });
writeOverrides(tmpDir, { overrides: { lodash: '4.18.1' } });
writeLock(tmpDir, { packages: ['lodash@4.18.1'] });
const violations = rule.analyze(context());
@@ -20,7 +20,7 @@ export class StaleOverridesRule extends BaseRule<CodeHealthContext> {
readonly id = 'stale-overrides';
readonly name = 'Stale Overrides';
readonly description =
'Detect pnpm.overrides that duplicate catalog entries, target packages absent from the dep graph, or are redundant against current resolution';
'Detect pnpm-workspace overrides that duplicate catalog entries, target packages absent from the dep graph, or are redundant against current resolution';
readonly severity = 'warning' as const;
analyze(context: CodeHealthContext): Violation[] {
@@ -29,13 +29,13 @@ export class StaleOverridesRule extends BaseRule<CodeHealthContext> {
const workspaceFile = (options.workspaceFile as string) ?? 'pnpm-workspace.yaml';
const lockFile = (options.lockFile as string) ?? 'pnpm-lock.yaml';
const overrides = parseOverrides(rootDir);
const overrides = parseOverrides(rootDir, workspaceFile);
if (overrides.length === 0) return [];
const catalogData = parseCatalog(rootDir, workspaceFile);
const lockData = parsePnpmLock(rootDir, lockFile);
const declaredRanges = scanDeclaredRanges(rootDir);
const filePath = path.join(rootDir, 'package.json');
const filePath = path.join(rootDir, workspaceFile);
return [
...this.findCatalogDuplicates(overrides, catalogData, filePath),
@@ -1,5 +1,6 @@
import * as fs from 'node:fs';
import * as path from 'node:path';
import { parse as parseYaml } from 'yaml';
export interface ParsedOverride {
rawKey: string;
@@ -10,23 +11,26 @@ export interface ParsedOverride {
line: number;
}
interface RootPackageJson {
pnpm?: { overrides?: Record<string, string> };
interface WorkspaceManifest {
overrides?: Record<string, string>;
}
export function parseOverrides(rootDir: string): ParsedOverride[] {
const filePath = path.join(rootDir, 'package.json');
export function parseOverrides(
rootDir: string,
workspaceFile = 'pnpm-workspace.yaml',
): ParsedOverride[] {
const filePath = path.join(rootDir, workspaceFile);
if (!fs.existsSync(filePath)) return [];
const content = fs.readFileSync(filePath, 'utf-8');
let pkg: RootPackageJson;
let workspace: WorkspaceManifest | null;
try {
pkg = JSON.parse(content) as RootPackageJson;
workspace = parseYaml(content) as WorkspaceManifest | null;
} catch {
return [];
}
const overrides = pkg.pnpm?.overrides;
const overrides = workspace?.overrides;
if (!overrides || typeof overrides !== 'object') return [];
const lines = content.split('\n');
@@ -47,15 +51,17 @@ export function parseOverrides(rootDir: string): ParsedOverride[] {
function findOverridesBlockStart(lines: string[]): number {
for (let i = 0; i < lines.length; i++) {
if (lines[i].includes('"overrides"')) return i;
if (/^overrides:\s*$/.test(lines[i])) return i;
}
return 0;
}
function findKeyLine(lines: string[], key: string, startIdx: number): number {
const needle = `"${key.replace(/"/g, '\\"')}"`;
const escaped = key.replace(/[.*+?^${}()|[\]\\]/g, '\\$&');
// Mapping keys are indented and may be single- or double-quoted.
const pattern = new RegExp(`^\\s+(['"]?)${escaped}\\1\\s*:`);
for (let i = startIdx; i < lines.length; i++) {
if (lines[i].includes(needle)) return i + 1;
if (pattern.test(lines[i])) return i + 1;
}
return startIdx + 1;
}
@@ -14,6 +14,7 @@
"devDependencies": {
"@codspeed/vitest-plugin": "^5.2.0",
"@n8n/expression-runtime": "workspace:*",
"vite": "catalog:",
"vitest": "catalog:",
"n8n-workflow": "workspace:*",
"typescript": "catalog:typescript"
+2665 -1522
View File
File diff suppressed because it is too large Load Diff
+208 -11
View File
@@ -1,3 +1,36 @@
strictDepBuilds: true
strictPeerDependencies: false
preferWorkspacePackages: true
autoInstallPeers: true
linkWorkspacePackages: deep
hoist: true
hoistWorkspacePackages: false
# pnpm 11 hoists TS7 into node_modules/.pnpm/node_modules, where it shadows the root's real
# TS6 and breaks vue-tsc — it needs `typescript/lib/_tsc`, which TS7 and the
# `@typescript/typescript6` alias both lack — in packages on the typescript-tooling catalog.
hoistPattern:
- '*'
- '!typescript'
allowUnusedPatches: true
pmOnFail: warn
fund: false
updateNotifier: false
loglevel: warn
packageImportMethod: clone-or-copy
minimumReleaseAge: 4320
minimumReleaseAgeExclude:
- '@n8n/*'
- '@n8n_io/*'
# Fresh Claude model IDs (e.g. Opus 5) ship in @ai-sdk/anthropic patches; allow
# installing before the 3-day minimumReleaseAge so agents/evals aren't stuck on
# the unknown-model 4096 max_tokens default.
- '@ai-sdk/anthropic'
# Security patch (Aikido) newer than the minimumReleaseAge window; allow it in.
- '@xmldom/xmldom'
packages:
- packages/*
- packages/@n8n/*
@@ -247,10 +280,11 @@ catalogs:
'@testing-library/jest-dom': ^6.6.3
'@testing-library/user-event': ^14.6.1
'@testing-library/vue': ^8.1.0
'@vitejs/plugin-vue': ^5.2.4
'@vitejs/plugin-vue': ^6.0.8
'@vue/test-utils': ^2.4.6
'@vue/tsconfig': ^0.7.0
'@vueuse/core': ^14.3.0
autoprefixer: ^10.4.19
element-plus: 2.4.3
highlight.js: 11.12.0
pinia: ^2.2.4
@@ -297,14 +331,177 @@ catalogs:
undici-v7:
undici: ^7.29.0
minimumReleaseAge: 4320
overrides:
libphonenumber-js: npm:empty-npm-package@1.0.0
'@browserbasehq/stagehand': npm:empty-npm-package@1.0.0
sharp: npm:empty-npm-package@1.0.0
ast-types: 0.16.1
baseline-browser-mapping: ^2.10.31
'@azure/identity': 4.13.0
'@lezer/common': ^1.2.0
'@mistralai/mistralai': ^1.10.0
'@n8n/typeorm>@sentry/node': catalog:sentry
'@opentelemetry/api': 'catalog:'
'@opentelemetry/core': 2.10.0
'@opentelemetry/propagator-jaeger': 2.10.0
'@types/node': ^20.17.50
chokidar: 4.0.3
esbuild: 'catalog:'
multer: ^2.2.0
prebuild-install: 7.1.3
pug: ^3.0.3
semver: 'catalog:'
tar-fs: 2.1.5
tslib: ^2.6.2
tsconfig-paths: ^4.2.0
vue-tsc: catalog:frontend
gaxios: '>=7.1.1'
google-gax: ^4.3.7
ws: '>=8.21.1'
date-fns: 2.30.0
date-fns-tz: 2.0.0
form-data: 4.0.6
pdf-parse: 'catalog:'
pdfjs-dist: 'catalog:'
tmp: 0.2.7
nodemailer: 8.0.10
validator: 13.15.26
zod: 3.25.76
js-yaml: 4.3.1
katex: 0.18.2
body-parser: 2.3.0
glob@10: 10.5.0
glob@7: 7.2.3
jws@3: 3.2.2
jws@4: 4.0.1
qs: 'catalog:'
'@smithy/config-resolver': '>=4.4.0'
'@rudderstack/rudder-sdk-node@<=3.0.0': 3.0.0
diff: 8.0.3
tar: 'catalog:'
ajv@6: 6.15.0
ajv@7: 8.20.0
ajv@8: 8.20.0
bn.js@4: 5.2.3
bn.js@5: 5.2.3
lodash: 4.18.1
minimatch@<=5.1.8: 5.1.8
minimatch@10: 10.2.3
'@hono/node-server': 1.19.15
follow-redirects: 1.16.0
express-rate-limit: 8.2.2
underscore: 1.13.8
flatted: 3.4.2
handlebars: 4.7.9
path-to-regexp: 8.4.0
path-to-regexp@<0.1.13: 0.1.13
picomatch@2: 2.3.2
picomatch@4: 4.0.4
avsc: 5.7.9
brace-expansion@<2.1.4: 2.1.4
'@xmldom/xmldom': 0.8.14
yaml@<=2.8.3: 2.8.3
axios: 'catalog:'
fast-xml-builder: 1.2.1
fast-xml-parser: 5.7.2
postcss@<=8.5.22: 8.5.23
'@anthropic-ai/sdk@<=0.91.1': 0.91.1
uuid@<=13.0.1: 13.0.1
fast-uri: 3.1.5
cjs-module-lexer@<2.2.0: 2.2.0
protobufjs: 7.6.5
shell-quote: 1.9.0
adm-zip: 0.6.0
ip-address@10: 10.3.1
brace-expansion@5: 5.0.9
'@tootallnate/once@2': 2.0.1
'@vue/server-renderer@3.5.26': 3.5.40
'@vue/shared@3.5.26': 3.5.40
'@opentelemetry/exporter-prometheus@<=0.217.0': 0.217.0
'@opentelemetry/sdk-node@<=0.217.0': 0.217.0
'@daytona/sdk@0.194.0>@aws-sdk/client-s3': 3.808.0
'@daytona/sdk@0.194.0>@aws-sdk/lib-storage': 3.808.0
'@daytona/sdk@0.194.0>@opentelemetry/sdk-trace-base': 2.7.1
langsmith: 0.6.0
hono: 4.12.34
'@tiptap/core': 'catalog:'
pg: 'catalog:'
file-type: 'catalog:'
linkify-it@<=5.0.1: 5.0.2
highlight.js@11: catalog:frontend
jose@<6.2.9: 6.2.9
node-rsa: 2.0.0
'@turbo/darwin-64@<=2.9.18': 2.9.18
'@turbo/linux-64@<=2.9.18': 2.9.18
'@turbo/windows-64@<=2.9.18': 2.9.18
ibm-cloud-sdk-core: ^5.5.0
undici@5: catalog:undici-v6
undici@6: catalog:undici-v6
undici@7: catalog:undici-v7
node-gyp>undici: catalog:undici-v7
'@babel/traverse': ^7.23.2
'@vitest/browser@<4.1.10': 4.1.10
immutable: 5.1.8
nanoid@<3.3.18: 'catalog:'
'@zone-eu/mailsplit@<5.4.15': 5.4.15
'strnum@<2.4.2': 2.4.2
minimumReleaseAgeExclude:
- '@n8n/*'
- '@n8n_io/*'
# Fresh Claude model IDs (e.g. Opus 5) ship in @ai-sdk/anthropic patches; allow
# installing before the 3-day minimumReleaseAge so agents/evals aren't stuck on
# the unknown-model 4096 max_tokens default.
- '@ai-sdk/anthropic'
# Security patch (Aikido) newer than the minimumReleaseAge window; allow it in.
- '@xmldom/xmldom'
patchedDependencies:
axios: patches/axios.patch
bull@4.16.4: patches/bull@4.16.4.patch
pdfjs-dist@5.4.296: patches/pdfjs-dist@5.4.296.patch
pkce-challenge@5.0.0: patches/pkce-challenge@5.0.0.patch
'@types/express-serve-static-core@5.0.6': patches/@types__express-serve-static-core@5.0.6.patch
'@types/ws@8.18.1': patches/@types__ws@8.18.1.patch
vue-tsc@2.2.8: patches/vue-tsc@2.2.8.patch
element-plus@2.4.3: patches/element-plus@2.4.3.patch
ics: patches/ics.patch
minifaker: patches/minifaker.patch
z-vue-scan: patches/z-vue-scan.patch
'@lezer/highlight': patches/@lezer__highlight.patch
v-code-diff: patches/v-code-diff.patch
vuedraggable@4.1.0: patches/vuedraggable@4.1.0.patch
assert@2.1.0: patches/assert@2.1.0.patch
reka-ui@2.5.0: patches/reka-ui@2.5.0.patch
lodash@4.18.1: patches/lodash@4.18.1.patch
'@langchain/openai@1.4.4': patches/@langchain__openai@1.4.4.patch
'@langchain/google-common@2.1.24': patches/@langchain__google-common@2.1.24.patch
'@confluentinc/kafka-javascript@1.9.1': patches/@confluentinc__kafka-javascript@1.9.1.patch
allowBuilds:
'@biomejs/biome': false
'@confluentinc/kafka-javascript': true
'@jitsi/robotjs': false
'@parcel/watcher': false
'@sentry-internal/node-cpu-profiler': false
'@sentry-internal/node-native-stacktrace': false
'@sentry/cli': false
'@sentry/node-cpu-profiler': false
'@sentry/node-native-stacktrace': false
'@swc/core': false
'@vscode/ripgrep': true
agent-browser: false
bufferutil: false
core-js: false
cpu-features: false
electron: false
electron-winstaller: false
es5-ext: false
esbuild: false
eslint-plugin-n8n-nodes-base: false
isolated-vm: true
lefthook: false
libpq: false
msgpackr-extract: false
oracledb: false
protobufjs: false
puppeteer: false
sleep: false
sqlite3: true
ssh2: false
tree-sitter: false
tree-sitter-bash: false
unrs-resolver: false
utf-8-validate: false
v-code-diff: false
vue-demi: false
+5 -47
View File
@@ -34,15 +34,6 @@ const config = {
rootDir: rootDir,
};
// Define backend patches to keep during deployment
const PATCHES_TO_KEEP = [
'pdfjs-dist',
'pkce-challenge',
'bull',
'lodash',
'@confluentinc/kafka-javascript',
];
// #endregion ===== Configuration =====
// #region ===== Helper Functions =====
@@ -144,43 +135,6 @@ if (process.env.CI !== 'true') {
}
// Run FE trim script
await $`cd ${config.rootDir} && node .github/scripts/trim-fe-packageJson.js`;
echo(chalk.yellow('INFO: Performing selective patch cleanup...'));
const packageJsonPath = path.join(config.rootDir, 'package.json');
if (await fs.pathExists(packageJsonPath)) {
try {
// 1. Read the package.json file
const packageJsonContent = await fs.readFile(packageJsonPath, 'utf8');
let packageJson = JSON.parse(packageJsonContent);
// 2. Modify the patchedDependencies directly in JavaScript
if (packageJson.pnpm && packageJson.pnpm.patchedDependencies) {
const filteredPatches = {};
for (const [key, value] of Object.entries(packageJson.pnpm.patchedDependencies)) {
// Check if the key (patch name) starts with any of the allowed patches
const shouldKeep = PATCHES_TO_KEEP.some((patchPrefix) => key.startsWith(patchPrefix));
if (shouldKeep) {
filteredPatches[key] = value;
}
}
packageJson.pnpm.patchedDependencies = filteredPatches;
}
// 3. Write the modified package.json back
await fs.writeFile(packageJsonPath, JSON.stringify(packageJson, null, 2), 'utf8');
echo(chalk.green('✅ Kept backend patches: ' + PATCHES_TO_KEEP.join(', ')));
echo(
chalk.gray(
`Removed FE/dev patches that are not in the list of backend patches to keep: ${PATCHES_TO_KEEP.join(', ')}`,
),
);
} catch (error) {
echo(chalk.red(`ERROR: Failed to cleanup patches in package.json: ${error.message}`));
process.exit(1);
}
}
echo(chalk.yellow(`INFO: Creating pruned production deployment in '${config.compiledAppDir}'...`));
startTimer('package_deploy');
@@ -201,9 +155,11 @@ if (excludeTestController) {
// top level, so cdxgen would miss the transitive tree (the manifest would be incomplete).
// Re-enable hoisting for the licenses build only — shipped images keep the non-hoisted
// layout, since regular builds leave N8N_GENERATE_LICENSES unset.
// `PNPM_CONFIG_*` and not `npm_config_*`: pnpm 11 no longer reads npm-style env config,
// so an `npm_config_` name here is silently ignored and the SBOM comes out incomplete.
const generateLicenses = process.env.N8N_GENERATE_LICENSES === 'true';
if (generateLicenses) {
process.env.npm_config_shamefully_hoist = 'true';
process.env.PNPM_CONFIG_SHAMEFULLY_HOIST = 'true';
}
await $`cd ${config.rootDir} && NODE_ENV=production DOCKER_BUILD=true pnpm --filter=n8n --prod --legacy deploy --no-optional ./compiled`;
@@ -253,6 +209,8 @@ const runtimeAssetGlobs = [
'*/@n8n/instance-ai/knowledge-base/*',
'*/dist/node-definitions/*',
];
echo(chalk.yellow('INFO: Verifying Runtime assets'));
for (const glob of runtimeAssetGlobs) {
const found = await $`find ${config.compiledAppDir} -type f -path ${glob}`.nothrow();
if (found.stdout.split('\n').filter(Boolean).length === 0) {