Fix hosted scan from a workspace member pinning nothing or the wrong files (#590, #417) - #598
Mikola Lysenko (mikolalysenko) wants to merge 5 commits into
Conversation
Assisted-by: Claude Code:claude-opus-5-5
Hosted scan and get read locks only in --cwd. Run from a pnpm workspace member (or a project whose lockfile-dir puts pnpm-lock.yaml elsewhere), they pinned nothing and still reported success, so pnpm kept installing the unpatched package (#590). Run from a cargo workspace member, they rewrote the member as a lockless project and broke every build of the workspace (#417). Both layouts are now refused before any takeover or write, exit 1, naming the directory to run from: redirect_pnpm_lockfile_elsewhere for pnpm, and the vendored cargo_manifest_not_workspace_root check, now shared, for cargo. Assisted-by: Claude Code:claude-opus-5-5
Assisted-by: Claude Code:claude-opus-5-5
|
BugBot review Generated by Claude Code |
|
[agent] CI note:
Generated by Claude Code |
A workspace root can move pnpm-lock.yaml with lockfileDir, and the key may be written quoted in pnpm-workspace.yaml. Hosted runs from a member of such a workspace, or of one with a quoted key, still reported success while pinning nothing. Both are now refused like any other member whose lock lives elsewhere. Assisted-by: Claude Code:claude-opus-5-5
|
BugBot review Generated by Claude Code |
|
[burn-down agent] Labeled Ready for review at
Generated by Claude Code |
|
Review updated for The original guard missed root The correction reads the nearest workspace's settings with native precedence (YAML, then member Validation passed: eight governing-root tests, all 16 pnpm CLI tests, and the Cargo member refusal test. Three new CLI regressions fail on the original head and pass with the fix. Native pnpm 10.34.5 offline installs verify inherited settings, path resolution, and precedence. Independent review of the final correction found no remaining issue; it merges cleanly with current main. No remaining code finding from this review. The Ready label has been restored after all checks completed on the corrected commit. |
|
bugbot run |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 93c3e32. Configure here.
Final-head CI is complete: 479 successful checks, 6 skipped; no failures or pending checks. Bugbot passed, there are no unresolved review threads, and the PR is mergeable.
Fixes #590 and #417. Hosted
scanandgetrun from a pnpm or Cargo workspace member can otherwise report success while reading only the member directory: pnpm pins nothing, and Cargo may rewrite member manifests as a lockless project, breaking workspace builds.The hosted path now refuses these layouts before takeover or writes, including dry runs. Cargo shares the existing vendored workspace-root check and reports
cargo_manifest_not_workspace_root. A pnpm candidate with no local npm-family lock reportsredirect_pnpm_lockfile_elsewherewhen its governing lock exists elsewhere, naming that lock and returning exit 1.pnpm resolution follows native configuration controls: the nearest workspace YAML takes precedence over member
.npmrc, which takes precedence over root.npmrc. Configured relativelockfileDir/lockfile-dirpaths resolve from the invocation directory; without an override, the lock is sought at the workspace root. Existing local locks and Rush bypass this ancestor check, and the nearest workspace bounds lookup. The disk check is shared by hosted scan/get; in-memory projects have no ancestor directory to inspect.Validation:
.npmrc, inherited relative YAML directory, and YAML precedence over member.npmrc. Refused runs preserve project and lock bytes.unused_variablesallowance), and the fixed commit merges cleanly with current main.93c3e32b.Other package managers' workspace-member rules remain outside this pnpm/Cargo change.
Note
Medium Risk
Changes hosted-mode entry preconditions and ancestor filesystem inspection for pnpm lock resolution; incorrect detection could block valid runs or still miss edge layouts, but refused runs are non-destructive.
Overview
Hosted
scanandget --mode hostednow fail closed when--cwdis a workspace member whose real lock or Cargo workspace root lives elsewhere, instead of exiting success with no pin or rewriting the wrong manifests.A new
governing_rootpre-check runs on disk projects before takeover or any writes (including--dry-run). pnpm npm candidates with no local npm-family lock getredirect_pnpm_lockfile_elsewhere, resolving the governingpnpm-lock.yamlusing pnpm-style precedence (pnpm-workspace.yamllockfileDir, then member/root.npmrc, relative paths from invocation cwd). Cargo candidates reuse the vendoredcargo_manifest_not_workspace_rootcheck with a hosted-specific message. Runs exit 1, write nothing, and tell the user which directory to use; workspace root runs still pin normally.Docs (CHANGELOG, CLI_CONTRACT) and broad unit/CLI regression tests cover workspace members,
lockfile-dir, inherited config, and the Cargo member case (#590, #417).Reviewed by Cursor Bugbot for commit 93c3e32. Configure here.