From d228d1f5ec7e460ff2befa5ec4545d7b488f83a3 Mon Sep 17 00:00:00 2001 From: Dotta Date: Fri, 4 Sep 2026 08:33:55 -0500 Subject: [PATCH] ci: preserve lockfile platform metadata during repair --- .github/scripts/tests/lockfile-refresh-workflows.test.mjs | 1 + .github/workflows/docker.yml | 4 ++-- .github/workflows/pr-trusted.yml | 2 +- .github/workflows/refresh-lockfile.yml | 2 +- 4 files changed, 5 insertions(+), 4 deletions(-) diff --git a/.github/scripts/tests/lockfile-refresh-workflows.test.mjs b/.github/scripts/tests/lockfile-refresh-workflows.test.mjs index 52fef1f698..7c19cf2cb9 100644 --- a/.github/scripts/tests/lockfile-refresh-workflows.test.mjs +++ b/.github/scripts/tests/lockfile-refresh-workflows.test.mjs @@ -17,6 +17,7 @@ test('lockfile repair workflows resolve dependencies instead of updating metadat assert.ok(repairCommands.length > 0, `${workflow} must contain a lockfile repair command`); for (const command of repairCommands) { + assert.match(command, /--resolution-only/); assert.match(command, /--ignore-scripts/); assert.doesNotMatch(command, /--lockfile-only/); } diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml index 5fb9f7e600..793568d0b5 100644 --- a/.github/workflows/docker.yml +++ b/.github/workflows/docker.yml @@ -87,7 +87,7 @@ jobs: - name: Refresh lockfile for Docker build context run: | set -euo pipefail - pnpm install --ignore-scripts --no-frozen-lockfile + pnpm install --resolution-only --ignore-scripts --no-frozen-lockfile changed="$(git status --porcelain)" if [ -z "$changed" ]; then @@ -281,7 +281,7 @@ jobs: - name: Refresh lockfile for Docker build context run: | set -euo pipefail - pnpm install --ignore-scripts --no-frozen-lockfile + pnpm install --resolution-only --ignore-scripts --no-frozen-lockfile changed="$(git status --porcelain)" if [ -z "$changed" ]; then diff --git a/.github/workflows/pr-trusted.yml b/.github/workflows/pr-trusted.yml index edbe655136..cc04e18fc4 100644 --- a/.github/workflows/pr-trusted.yml +++ b/.github/workflows/pr-trusted.yml @@ -346,7 +346,7 @@ jobs: id: regen_lockfile run: | cp pnpm-lock.yaml "$RUNNER_TEMP/pnpm-lock.before.yaml" - pnpm install --ignore-scripts --no-frozen-lockfile + pnpm install --resolution-only --ignore-scripts --no-frozen-lockfile if cmp -s "$RUNNER_TEMP/pnpm-lock.before.yaml" pnpm-lock.yaml; then echo "regenerated=0" >> "$GITHUB_OUTPUT" else diff --git a/.github/workflows/refresh-lockfile.yml b/.github/workflows/refresh-lockfile.yml index 039d21970e..df9bd7abef 100644 --- a/.github/workflows/refresh-lockfile.yml +++ b/.github/workflows/refresh-lockfile.yml @@ -35,7 +35,7 @@ jobs: cache: pnpm - name: Refresh pnpm lockfile - run: pnpm install --ignore-scripts --no-frozen-lockfile + run: pnpm install --resolution-only --ignore-scripts --no-frozen-lockfile - name: Fail on unexpected file changes run: |