Repository navigation
fix(extensions): declare the typescript peer for the Volar packages - #7232
Merged
Merged
Conversation
2 tasks done
arcanis
added a commit
to yarnpkg/zpm
that referenced
this pull request
Aug 15, 2026
## What's the problem this PR addresses? A review of recent Berry PRs identified several fixes and regression tests that also apply to zpm. This PR backports them in one batch. ## How did I fix it? **Bug fixes (the ported regression tests reproduced each of these before the fix):** - yarnpkg/berry#7205 — `*` now resolves to prereleases when a package has no stable version. The fallback only applies to a literal `*` range (not the internal `>=0.0.0-0` any-range), and `--check-resolutions` accepts the resulting prerelease pins. - yarnpkg/berry#7216 — the nm linker now prefers direct dependency binaries over transitively-hoisted aliases when two packages expose the same bin name, instead of resolving collisions by ident order. - yarnpkg/berry#7209 — commands that need an npm OTP now fail with a `--otp` hint when not attached to an interactive terminal, instead of blocking forever on a prompt. - yarnpkg/berry#7255 — `yarn npm audit --recursive --environment production` no longer reports advisories only reachable through a nested workspace's devDependencies. - yarnpkg/berry#7253 — `yarn info --virtuals` now reports base descriptors alongside virtual locators (zpm had the mirror image of Berry's bug: correct locators, virtualized descriptors). - yarnpkg/berry#7206 — a failed Algolia auto-types lookup no longer aborts `yarn add`; it degrades to a warning (with the `enableAutoTypes` escape hatch) and the lookup is bounded by a 10s per-request timeout. **Feature:** - yarnpkg/berry#7243 — `supportedArchitectures` additionally accepts a list of explicit os/cpu/libc combinations (matched per-entry, no cross-product), with the same config syntax as Berry. **Tests only (zpm's behavior was already correct):** - yarnpkg/berry#7250 / yarnpkg/berry#7257 — gate bypass for packages without release-time metadata, plus the `no-time-deps` fixture and registry-mock support. - yarnpkg/berry#7214 — scoped-gate inheritance tests, adapted to zpm's `packageRules`/`sourceRules` model (zpm's Option-based overrides make Berry's default-shadowing bug structurally impossible). **Artifact sync:** - Re-ran `scripts/import-artifacts.mjs` against Berry master, picking up yarnpkg/berry#7232 and the extensions hunk of yarnpkg/berry#7228 (8 new package extensions: 5 Volar `typescript` peers, `vite-plugin-vue-devtools`, 2 Parcel entries) along with forward-only PnP hook/patch updates. ## Checklist - [x] I have read the [Contributing Guide](https://yarnpkg.com/advanced/contributing). - [x] I have checked that all the impacted tests pass: the touched acceptance suites (npmMinimalAgeGate, prunedNativeDeps, protocols/npm, npm/audit, info, publish, node-modules, packageExtensions, checkResolutions, add) pass 215/218 (3 skipped), plus `cargo test` for zpm-config (7) and zpm-semver (108). The only remaining local failures reproduce identically on a pristine `main` build (venv/Python environment, one live-Algolia-data test, `path_iterators` and two lazyInstalls focus-coverage tests). <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Medium Risk** > Touches core install resolution, architecture filtering, and audit traversal; behavior changes are intentional but affect many installs and multi-arch fetches. > > **Overview** > Backports a batch of Berry fixes and tests into zpm, covering install resolution, CLI behavior, configuration, and artifact sync. > > **Resolution & install:** Literal `*` ranges can resolve to prereleases when no stable versions exist, with matching `--check-resolutions` acceptance. Algolia auto-`@types` lookup is capped at 10s, warns instead of failing `yarn add`, and respects `enableAutoTypes`. HTTP requests gain a per-request `.timeout()` bounded by `httpTimeout`. > > **Commands & linkers:** `npm publish` errors with a `--otp` hint when not on an interactive TTY. Recursive production `npm audit` skips nested workspaces’ devDependencies. `yarn info --virtuals` shows physical descriptors with virtual locators. Node-modules bin symlinks prefer direct dependencies over hoisted aliases. > > **`supportedArchitectures`:** Schema becomes a `oneOrMany` list of entries with `ArchitectureFilter` fields (`null` = any). Legacy single-object YAML still works; project config replaces (not merges) user entries. Matching uses `SystemSet` / `supported_systems()` with per-entry validation instead of a flat cross-product of all systems. > > **Artifacts:** `builtin-extensions.json` gains Volar, Vite devtools, and Parcel peer entries; package manager pin updated. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 4aaf6a1. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY -->
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What's the problem this PR addresses?
Five packages in the Volar ecosystem import
typescriptfrom their published type declarations without declaring it independenciesorpeerDependencies:.d.tsfiles importingtypescript@volar/typescriptindex.d.ts:9—import type * as ts from 'typescript'@volar/language-serverlib/project/typescriptProject.d.ts:2@volar/language-servicelib/types.d.ts:2volar-service-typescriptindex.d.ts:4—create(ts: typeof import('typescript'), …)volar-service-typescript-twoslash-queriesindex.d.ts:2With a hoisting installer this resolves by accident. Under an isolated layout it only resolves when the package's real path happens to sit beneath a
node_modulesthat hastypescriptas an ancestor, so it works in some projects and silently breaks in others. When it breaks,tscreportsTS2307: Cannot find module 'typescript'from inside the published.d.ts, everyts.*type degrades toany, and downstreamdeclare moduleaugmentation stops applying — which surfaces as errors that look unrelated to a missing dependency, e.g.Property 'typescript' does not exist on type 'ProjectContext'.This came out of triaging a pnpm report against Astro's language-tools packages: pnpm/pnpm#13331.
How did you fix it?
Added the five packages to the compatibility database with an optional
typescriptpeer dependency. Optional is deliberate: all five receive thetsinstance from their caller and neverrequire('typescript')themselves, so a required peer would pull TypeScript into projects that only consume the runtime.Verified on a reduced project (
@volar/typescript+typescript, installed so the package resolves outside the project tree): without the extensiontscreports theTS2307s above plus a downstreamTS7006; with the equivalent extension applied it compiles clean, with no other change.Two notes for reviewers:
@volar/typescriptis [BUG] Consider addingtypescriptas a dependency in the@volar/typescriptpackage volarjs/volar.js#284, open since 2025-08-07 with no maintainer response; I've added the reproduction and the two additional packages from that repo to it. The twovolar-service-*packages live in a different repo and had no report at all, so I opened volar-service-typescript and volar-service-typescript-twoslash-queries importtypescripttypes without declaring it volarjs/services#125. I know the convention here is to link an upstream PR rather than an issue — happy to send PRs to both Volar repos and update these comments with the URLs if you'd prefer that before merging.*rather than an upper bound because all five are still unfixed at their latest release. If they later declare the peer themselves the extension becomes a no-op. Happy to switch to<=2.4.28/<=0.0.71if you'd rather bound it.The
.yarn/versionsentry was written by hand rather than viayarn version check --interactive(I didn't want to run a full install of this repo just for the bump file) — tell me if it needs regenerating.Written by an agent (Claude Code, claude-opus-5), on behalf of the pnpm maintainers.