Home

dev / openkara

publicthedavidweng/OpenKara· sync paused
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

chore(tooling): upgrade pnpm to 12.5.1

open
Stack 2/2
#457 opened by devcursor/pnpm-12-27b8→feat/418-online-sources
Conversation4
devopened this pull requestAuthor· last week
Commits
0
Files changed…

Summary

Upgrade the OpenKara toolchain from pnpm 11.20.0 to pnpm 12.5.1.

package.json now pins "packageManager": "pnpm@12.5.1" and engines.pnpm to the same version. mise.toml uses pnpm = "12" so mise tracks the 12.x line. GitHub Actions pnpm/action-setup versions are aligned to 12.5.1.

Changes

  • Pin pnpm 12.5.1 in package.json (packageManager + engines.pnpm) and set mise.toml to pnpm = "12".
  • Align CI / packaging / release / installed-app / separation-smoke pnpm/action-setup versions to 12.5.1.
  • Flatpak: vendor pnpm-12.5.1.tgz plus [@pnpm](/pnpm)/exe.linux-x64 and [@pnpm](/pnpm)/exe.linux-arm64. pnpm 12 is a native binary and no longer ships dist/worker.js, so the old extract-worker populate step is replaced with pnpm fetch --offline after rewriting lockfile resolutions to file: tarballs.
  • Keep pnpm-lock.yaml as a single YAML document via pmOnFail: ignore. pnpm 12 otherwise writes a leading env document (packageManagerDependencies) that GitHub's dependency graph and the Flatpak lockfile parsers cannot read.
  • Lockfile parsers now take the last YAML document as a defense in depth.

Acceptance criteria

  • Local corepack / pnpm 12.5.1 installs the existing lockfile with --frozen-lockfile.
  • CI jobs that pin pnpm use 12.5.1.
  • Flatpak manifest tarball URLs match packageManager.
  • Flatpak packaging tests pass, including store version v11 (pnpm 12 still uses store-dir/v11).

Test plan

  • pnpm lint — PASS (pre-push)
  • pnpm format — PASS (pre-push)
  • pnpm vitest run — PASS (2415 tests, pre-push)
  • pnpm build / node --run build — PASS
  • cd src-tauri && cargo clippy --all-targets -- -D warnings — skipped (no Rust changes)
  • cd src-tauri && cargo nextest run — skipped (no Rust changes)
  • node --run check:i18n — skipped (no UI copy)
  • docs/references/contracts/*.md — not applicable (no IPC change)
  • Product-standard profile Security, privacy, and release reviewed. Evidence: dependency pin alignment, CI version alignment, Flatpak tarball/digest match, single-document lockfile for GitHub dependency graph (NIST SSDF 1.1 dependency/build control). No SLSA/SBOM claim.

Related issues

Follows the pnpm 12 upgrade request on feat/418-online-sources.

Open in Web Open in Cursor 
coderabbitai[bot]commented· last week

[!IMPORTANT]

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share
  • X
  • Mastodon
  • Reddit
  • LinkedIn

Comment [@coderabbitai](/coderabbitai) help to get the list of available commands.

github-actions[bot]commented· last week

Coverage Report

Status Category Percentage Covered / Total
🟢 Lines 84.45% (🎯 65%) 8127 / 9623
🟢 Statements 83.64% (🎯 65%) 8618 / 10303
🟢 Functions 79.71% (🎯 60%) 2039 / 2558
🟢 Branches 76.39% (🎯 60%) 4615 / 6041
File CoverageNo changed files found.
Generated in workflow #1869 for commit 1c597d2 by the Vitest Coverage Report Action
codecov[bot]commented· last week

Codecov Report

:white_check_mark: All modified and coverable lines are covered by tests. :white_check_mark: Project coverage is 88.3%. Comparing base (982f350) to head (1c597d2). :white_check_mark: All tests successful. No failed tests found.

Additional details and impacted files
@@                    Coverage Diff                    @@
##           feat/418-online-sources    #457     +/-   ##
=========================================================
- Coverage                     88.3%   88.3%   -0.1%
=========================================================
  Files                          219     219
  Lines                        11686   11686
  Branches                      3598    3598
=========================================================
- Hits                         10329   10328      -1
- Misses                        1304    1305      +1
  Partials                        53      53
FlagCoverage Δ
frontend88.3% <ø> (-0.1%):arrow_down:

Flags with carried forward coverage won't be shown. Click here to find out more.

ComponentsCoverage Δ
frontend88.3% <ø> (-0.1%):arrow_down:
rust∅ <ø> (∅)
see 1 file with indirect coverage changes
:rocket: New features to boost your workflow:
  • :package: JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.
devcommented· last week

Status (triage 2026-09-21)

Left as Draft — still WIP, not abandoned, not ready to merge.

ItemValue
Basefeat/418-online-sources (feature branch, not main)
Headcursor/pnpm-12-27b8
Base packageManagerpnpm@11.20.0
main packageManagerpnpm@11.20.0
This branchpnpm@12.5.1
MergeableCONFLICTING (DIRTY)
CI on headLargely green when last run (CI Gate, JS quality, Flatpak, Rust/Win/macOS/Linux builds SUCCESS)

Findings

  1. Upgrade is not superseded. Neither main nor the base feature branch has moved past pnpm 11.20.0. This branch is still the only place carrying pnpm 12.5.1 + Flatpak vendor tarballs + lockfile single-document handling.
  2. Conflicts are against the feature base, not a stale Dependabot bump. Parent feature PR #419 (feat(catalog): add Online Sources…) is also still open/BLOCKED against main. Rebase order matters: land or rebase #419 first, then rebase this toolchain PR onto the updated feature branch (or onto main if #419 is being abandoned/rewritten).
  3. Do not undraft yet. Flatpak vendor path + pnpm-12 lockfile quirks (pmOnFail: ignore / last-YAML-document parsing) need a green rebase CI run after the base moves.

Next step (when ready)

# after feat/418-online-sources is rebased onto current main (or #419 merges)
git fetch origin
git rebase origin/feat/418-online-sources   # or origin/main if retargeting
# resolve package.json / mise.toml / workflow pnpm pins / lockfile conflicts
# keep packageManager + engines.pnpm + pnpm/action-setup aligned at 12.5.1

No status change made — draft remains draft.

This branch can’t be merged automatically yet
Branch comparison failed — verify branches still exist in storage.
0 approving reviews
None yet
Checks
No checks recorded
Fast-forward
Source must contain the target branch tip
feat/418-online-sources ← cursor/pnpm-12-27b8

Sign in to comment.

Stack

2/2
1

Merge readiness

Checking mergeability after the indexing worker computes the current branch state.

Autopilot

Debug

Reviews

Approved0
ReviewersNone yet

Configure an OpenRouter key in repository settings.

feat(catalog): add Online Sources for NetEase import and YouTube queue

#419 main ← feat/418-online-sources

Updated last month

open
2

chore(tooling): upgrade pnpm to 12.5.1

#457 feat/418-online-sources ← cursor/pnpm-12-27b8

Updated last week

open