Skip to content

Pin pnpm version for FAB and Edge3 UI so bumps keep security overrides - #72390

Merged
bbovenzi merged 1 commit into
apache:mainfrom
aws-mwaa:fix-fab-dependabot-pnpm-version
Sep 2, 2026
Merged

bbovenzi merged 1 commit into
apache:mainfrom
aws-mwaa:fix-fab-dependabot-pnpm-version

Conversation

@vincbeck

@vincbeck vincbeck commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

These were the only two pnpm directories in the repo without a packageManager field. Without it, Dependabot resolves them with pnpm 11, which no longer reads pnpm.overrides from package.json. It therefore regenerates pnpm-lock.yaml with the overrides: block missing entirely, silently dropping the pinned security patches for transitive dependencies and breaking frozen installs for the pnpm 10 that the asset-compilation hooks use.

The version matches the one already used everywhere else in the repo.


Was generative AI tooling used to co-author this PR?
  • Yes (please specify the tool below)

  • Read the Pull Request Guidelines for more information. Note: commit author/co-author name and email in commits become permanently public when merged.
  • For fundamental code changes, an Airflow Improvement Proposal (AIP) is needed.
  • When adding dependency, check compliance with the ASF 3rd Party License Policy.
  • For significant user-facing changes create newsfragment: {pr_number}.significant.rst, in airflow-core/newsfragments. You can add this file in a follow-up commit after the PR is created so you know the PR number.

These were the only two pnpm directories in the repo without a
`packageManager` field. Without it, Dependabot resolves them with pnpm 11,
which no longer reads `pnpm.overrides` from `package.json`. It therefore
regenerates `pnpm-lock.yaml` with the `overrides:` block missing entirely,
silently dropping the pinned security patches for transitive dependencies and
breaking frozen installs for the pnpm 10 that the asset-compilation hooks use.

The version matches the one already used everywhere else in the repo.
@bbovenzi
bbovenzi merged commit 38401f8 into apache:main Sep 2, 2026
76 checks passed
vincbeck added a commit to aws-mwaa/upstream-to-airflow that referenced this pull request Sep 9, 2026
Without a `packageManager` field, Dependabot resolves these directories with
pnpm 11, which no longer reads `pnpm.overrides` from `package.json`. It
regenerates `pnpm-lock.yaml` with the `overrides:` block missing entirely,
silently dropping the pinned security patches for transitive dependencies and
breaking the frozen installs that the lint and asset-compilation hooks rely on.

Two lockfiles on this branch had already lost their overrides that way, so they
are restored here with the pinned pnpm. The version matches the one the static
checks on this branch already install.

Backport of apache#71516 and apache#72390, which pin the same field on main.
vincbeck added a commit to aws-mwaa/upstream-to-airflow that referenced this pull request Sep 9, 2026
Without a `packageManager` field, Dependabot resolves these directories with
pnpm 11, which no longer reads `pnpm.overrides` from `package.json`. It
regenerates `pnpm-lock.yaml` with the `overrides:` block missing entirely,
silently dropping the pinned security patches for transitive dependencies and
breaking the frozen installs that the lint and asset-compilation hooks rely on.

Two lockfiles on this branch had already lost their overrides that way, so they
are restored here with the pinned pnpm. The version matches the one the static
checks on this branch already install.

Backport of apache#71516 and apache#72390, which pin the same field on main.
vincbeck added a commit to aws-mwaa/upstream-to-airflow that referenced this pull request Sep 9, 2026
Without a `packageManager` field, Dependabot resolves these directories with
pnpm 11, which no longer reads `pnpm.overrides` from `package.json`. It
regenerates `pnpm-lock.yaml` with the `overrides:` block missing entirely,
silently dropping the pinned security patches for transitive dependencies and
breaking the frozen installs that the lint and asset-compilation hooks rely on.

Two lockfiles on this branch had already lost their overrides that way, so they
are restored here with the pinned pnpm. The version matches the one the static
checks on this branch already install.

Backport of apache#71516 and apache#72390, which pin the same field on main.
vincbeck added a commit to aws-mwaa/upstream-to-airflow that referenced this pull request Sep 9, 2026
Without a `packageManager` field, Dependabot resolves these directories with
pnpm 11, which no longer reads `pnpm.overrides` from `package.json`. It
regenerates `pnpm-lock.yaml` with the `overrides:` block missing entirely,
silently dropping the pinned security patches for transitive dependencies and
breaking the frozen installs that the lint and asset-compilation hooks rely on.

Two lockfiles on this branch had already lost their overrides that way, so they
are restored here with the pinned pnpm. The version matches the one the static
checks on this branch already install.

Backport of apache#71516 and apache#72390, which pin the same field on main.
bbovenzi pushed a commit that referenced this pull request Sep 9, 2026
…#72816)

Without a `packageManager` field, Dependabot resolves these directories with
pnpm 11, which no longer reads `pnpm.overrides` from `package.json`. It
regenerates `pnpm-lock.yaml` with the `overrides:` block missing entirely,
silently dropping the pinned security patches for transitive dependencies and
breaking the frozen installs that the lint and asset-compilation hooks rely on.

Two lockfiles on this branch had already lost their overrides that way, so they
are restored here with the pinned pnpm. The version matches the one the static
checks on this branch already install.

Backport of #71516 and #72390, which pin the same field on main.
imrichardwu pushed a commit to imrichardwu/airflow that referenced this pull request Sep 11, 2026
apache#72390)

These were the only two pnpm directories in the repo without a
`packageManager` field. Without it, Dependabot resolves them with pnpm 11,
which no longer reads `pnpm.overrides` from `package.json`. It therefore
regenerates `pnpm-lock.yaml` with the `overrides:` block missing entirely,
silently dropping the pinned security patches for transitive dependencies and
breaking frozen installs for the pnpm 10 that the asset-compilation hooks use.

The version matches the one already used everywhere else in the repo.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:providers provider:edge Edge Executor / Worker (AIP-69) / edge3 provider:fab

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants