build: migrate JavaScript tooling to pnpm 11 - #1792
Merged
Merged
Conversation
eitsupi
marked this pull request as draft
September 28, 2026 14:17
eitsupi
marked this pull request as ready for review
September 28, 2026 14:22
# Conflicts: # package-lock.json # package.json
eitsupi
requested review from
ManuelHentschel
and
a balanced review from Copilot
October 2, 2026 12:37
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The migration is consistent across configuration, development tasks, CI, packaging, and release workflows with no unresolved correctness issues.
Review effort: Balanced
Findings: None
What changed in this PR
Migrates JavaScript tooling from npm to pinned pnpm 11 with reproducible installs and safer extension packaging.
Changes:
- Replaces npm lock/install workflows with pnpm and frozen lockfiles.
- Uses declared local release tools and explicit dependency-build permissions.
- Updates packaging exclusions, VS Code tasks, and contributor documentation.
| File | Description |
|---|---|
package-lock.json |
Removes the npm lockfile. |
pnpm-lock.yaml |
Adds pnpm’s dependency lockfile. |
pnpm-workspace.yaml |
Controls dependency build-script permissions. |
package.json |
Pins pnpm and declares local tooling. |
tsconfig.json |
Restricts compilation to source TypeScript. |
.vscodeignore |
Defines an allowlist for VSIX contents. |
.vscode/tasks.json |
Migrates tasks to pnpm. |
.vscode/launch.json |
References the renamed pnpm-backed tasks. |
.github/workflows/main.yml |
Migrates CI installation and commands. |
.github/workflows/pre-release.yml |
Migrates pre-release packaging. |
.github/workflows/release.yml |
Uses reproducible installs and local publishing tools. |
CONTRIBUTING.md |
Updates contributor commands for pnpm. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
ManuelHentschel
approved these changes
Oct 2, 2026
ManuelHentschel
left a comment
Member
There was a problem hiding this comment.
I did a quick check on my local machine and the build seems to work fine.
Member
Author
|
Thanks! |
2 of 5 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of #1732.
I used https://github.com/oxc-project/oxc-vscode as a reference.
Why
Before updating the dependency backlog, we need a safer baseline for installing and running JavaScript tools. pnpm 11 denies dependency build scripts unless they are explicitly reviewed, applies a default cooldown to newly published packages, and exposes undeclared dependency assumptions through its isolated node_modules layout. This PR keeps those protections enabled.
The value here is combining an exact package-manager pin, pnpm's installation safeguards, and project-declared CLI tools. Release jobs should not fetch executables through npx at execution time.
Changes
@vscode/vsceandovsxas devDependencies; use project-local binaries for them andgit-cliff.esbuild's dependency build script, which prepares its platform-specific binary. Explicitly deny vsce-sign and keytar because these workflows do not sign VSIX files or use vsce's credential store.vsce --no-dependencies, and include only required files in the VSIX.Verification
A clean checkout completed
pnpm install --frozen-lockfileandpnpm run compilewithout changing tracked files. TypeScript pretest and VSIX packaging passed with Node 24. ESLint passed with 48 existing warnings and no errors. The VSIX contains no node_modules, source maps, or development files.