Skip to content

[v3-3-test] Pin pnpm for UI packages so bumps keep security overrides - #72816

Merged
bbovenzi merged 1 commit into
apache:v3-3-testfrom
aws-mwaa:pin-pnpm-package-manager-v3-3-test
Sep 9, 2026
Merged

bbovenzi merged 1 commit into
apache:v3-3-testfrom
aws-mwaa:pin-pnpm-package-manager-v3-3-test

Conversation

@vincbeck

@vincbeck vincbeck commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Without a packageManager field, Dependabot resolves these directories with pnpm 11, which no longer reads pnpm.overrides from package.json. It regenerates pnpm-lock.yaml with the overrides: block missing entirely, silently dropping the pinned security patches for transitive dependencies and breaking the frozen installs that the lint and asset-compilation hooks rely on.

Two lockfiles on this branch had already lost their overrides that way, so they are restored here with the pinned pnpm. The version matches the one the static checks on this branch already install.

Backport of #71516 and #72390, which pin the same field on main.


Was generative AI tooling used to co-author this PR?
  • Yes (please specify the tool below)

  • Read the Pull Request Guidelines for more information. Note: commit author/co-author name and email in commits become permanently public when merged.
  • For fundamental code changes, an Airflow Improvement Proposal (AIP) is needed.
  • When adding dependency, check compliance with the ASF 3rd Party License Policy.
  • For significant user-facing changes create newsfragment: {pr_number}.significant.rst, in airflow-core/newsfragments. You can add this file in a follow-up commit after the PR is created so you know the PR number.

Without a `packageManager` field, Dependabot resolves these directories with
pnpm 11, which no longer reads `pnpm.overrides` from `package.json`. It
regenerates `pnpm-lock.yaml` with the `overrides:` block missing entirely,
silently dropping the pinned security patches for transitive dependencies and
breaking the frozen installs that the lint and asset-compilation hooks rely on.

Two lockfiles on this branch had already lost their overrides that way, so they
are restored here with the pinned pnpm. The version matches the one the static
checks on this branch already install.

Backport of apache#71516 and apache#72390, which pin the same field on main.
@boring-cyborg boring-cyborg Bot added area:API Airflow's REST/HTTP API area:dev-tools area:UI Related to UI/UX. For Frontend Developers. labels Sep 9, 2026
@vatsrahul1001 vatsrahul1001 added this to the Airflow 3.3.2 milestone Sep 9, 2026
@vatsrahul1001 vatsrahul1001 added the changelog:skip Changes that should be skipped from the changelog (CI, tests, etc..) label Sep 9, 2026
@bbovenzi
bbovenzi merged commit 23e38df into apache:v3-3-test Sep 9, 2026
82 checks passed
vatsrahul1001 added a commit that referenced this pull request Sep 11, 2026
The fast-uri@3.1.5 pulled into the FAB provider www lockfile by earlier
dependabot bumps is affected by four high-severity advisories (SSRF and
host-confusion). Pin pnpm and add a security override so the version
stays on the patched 3.1.x line, mirroring the treatment #72816 applied
to the other UI packages but skipped for the FAB provider.
@vincbeck
vincbeck deleted the pin-pnpm-package-manager-v3-3-test branch September 21, 2026 17:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:API Airflow's REST/HTTP API area:dev-tools area:UI Related to UI/UX. For Frontend Developers. changelog:skip Changes that should be skipped from the changelog (CI, tests, etc..)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants