Skip to content

Fix pnpm version in package.json until we upgrade - #71516

Merged
potiuk merged 1 commit into
apache:mainfrom
astronomer:fix-pnpm-version
Aug 13, 2026
Merged

potiuk merged 1 commit into
apache:mainfrom
astronomer:fix-pnpm-version

Conversation

@bbovenzi

Copy link
Copy Markdown
Contributor

If a user has pnpm > 11 installed locally. They will end up with a different lock file than main and the "pnpm" section of package.json will be deprecated.

I will open another PR to migrate pnpm to >11 but for now let's explicitly call out the pnpm version to use so that we don't break development


Was generative AI tooling used to co-author this PR?
  • Yes (please specify the tool below)

  • Read the Pull Request Guidelines for more information. Note: commit author/co-author name and email in commits become permanently public when merged.
  • For fundamental code changes, an Airflow Improvement Proposal (AIP) is needed.
  • When adding dependency, check compliance with the ASF 3rd Party License Policy.
  • For significant user-facing changes create newsfragment: {pr_number}.significant.rst, in airflow-core/newsfragments. You can add this file in a follow-up commit after the PR is created so you know the PR number.

@potiuk

potiuk commented Aug 13, 2026

Copy link
Copy Markdown
Member

temp issue only with helm download

@potiuk
potiuk merged commit bdfe789 into apache:main Aug 13, 2026
151 of 152 checks passed
@github-actions

Copy link
Copy Markdown
Contributor

Backport failed to create: v3-3-test. View the failure log Run details

Note: As of Merging PRs targeted for Airflow 3.X
the committer who merges the PR is responsible for backporting the PRs that are bug fixes (generally speaking) to the maintenance branches.

In matter of doubt please ask in #release-management Slack channel.

Status Branch Result
❌ v3-3-test Commit Link

You can attempt to backport this manually by running:

cherry_picker bdfe789 v3-3-test

This should apply the commit to the v3-3-test branch and leave the commit in conflict state marking
the files that need manual conflict resolution.

After you have resolved the conflicts, you can continue the backport process by running:

cherry_picker --continue

If you don't have cherry-picker installed, see the installation guide.

dabla pushed a commit to dabla/airflow that referenced this pull request Aug 14, 2026
vincbeck added a commit to aws-mwaa/upstream-to-airflow that referenced this pull request Sep 9, 2026
Without a `packageManager` field, Dependabot resolves these directories with
pnpm 11, which no longer reads `pnpm.overrides` from `package.json`. It
regenerates `pnpm-lock.yaml` with the `overrides:` block missing entirely,
silently dropping the pinned security patches for transitive dependencies and
breaking the frozen installs that the lint and asset-compilation hooks rely on.

Two lockfiles on this branch had already lost their overrides that way, so they
are restored here with the pinned pnpm. The version matches the one the static
checks on this branch already install.

Backport of apache#71516 and apache#72390, which pin the same field on main.
vincbeck added a commit to aws-mwaa/upstream-to-airflow that referenced this pull request Sep 9, 2026
Without a `packageManager` field, Dependabot resolves these directories with
pnpm 11, which no longer reads `pnpm.overrides` from `package.json`. It
regenerates `pnpm-lock.yaml` with the `overrides:` block missing entirely,
silently dropping the pinned security patches for transitive dependencies and
breaking the frozen installs that the lint and asset-compilation hooks rely on.

Two lockfiles on this branch had already lost their overrides that way, so they
are restored here with the pinned pnpm. The version matches the one the static
checks on this branch already install.

Backport of apache#71516 and apache#72390, which pin the same field on main.
vincbeck added a commit to aws-mwaa/upstream-to-airflow that referenced this pull request Sep 9, 2026
Without a `packageManager` field, Dependabot resolves these directories with
pnpm 11, which no longer reads `pnpm.overrides` from `package.json`. It
regenerates `pnpm-lock.yaml` with the `overrides:` block missing entirely,
silently dropping the pinned security patches for transitive dependencies and
breaking the frozen installs that the lint and asset-compilation hooks rely on.

Two lockfiles on this branch had already lost their overrides that way, so they
are restored here with the pinned pnpm. The version matches the one the static
checks on this branch already install.

Backport of apache#71516 and apache#72390, which pin the same field on main.
vincbeck added a commit to aws-mwaa/upstream-to-airflow that referenced this pull request Sep 9, 2026
Without a `packageManager` field, Dependabot resolves these directories with
pnpm 11, which no longer reads `pnpm.overrides` from `package.json`. It
regenerates `pnpm-lock.yaml` with the `overrides:` block missing entirely,
silently dropping the pinned security patches for transitive dependencies and
breaking the frozen installs that the lint and asset-compilation hooks rely on.

Two lockfiles on this branch had already lost their overrides that way, so they
are restored here with the pinned pnpm. The version matches the one the static
checks on this branch already install.

Backport of apache#71516 and apache#72390, which pin the same field on main.
bbovenzi pushed a commit that referenced this pull request Sep 9, 2026
…#72816)

Without a `packageManager` field, Dependabot resolves these directories with
pnpm 11, which no longer reads `pnpm.overrides` from `package.json`. It
regenerates `pnpm-lock.yaml` with the `overrides:` block missing entirely,
silently dropping the pinned security patches for transitive dependencies and
breaking the frozen installs that the lint and asset-compilation hooks rely on.

Two lockfiles on this branch had already lost their overrides that way, so they
are restored here with the pinned pnpm. The version matches the one the static
checks on this branch already install.

Backport of #71516 and #72390, which pin the same field on main.
imrichardwu pushed a commit to imrichardwu/airflow that referenced this pull request Sep 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:API Airflow's REST/HTTP API area:dev-tools area:UI Related to UI/UX. For Frontend Developers.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants