Skip to content

Give pnpm installs pnpm upgrade commands (#1111) - #1350

Merged
Mikola Lysenko (mikolalysenko) merged 4 commits into
mainfrom
agent/v5-update-pnpm-channel
Oct 9, 2026
Merged

Mikola Lysenko (mikolalysenko) merged 4 commits into
mainfrom
agent/v5-update-pnpm-channel

Conversation

@mikolalysenko

@mikolalysenko Mikola Lysenko (mikolalysenko) commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

LLM Description written by Claude Code:claude-opus-5-5

Fixes #1111

Summary

socket-patch --update (and the passive update notice, which shares the same hint) now tells a pnpm install to upgrade through pnpm and labels the refusal "managed by pnpm".

Install Before After
pnpm global store npm update -g @socketsecurity/socket-patch (a no-op: npm never sees pnpm's store) pnpm add -g @socketsecurity/socket-patch@latest
pnpm project npm install @socketsecurity/socket-patch@latest (writes a stray package-lock.json; next pnpm install --frozen-lockfile fails) pnpm add @socketsecurity/socket-patch@latest
pnpm workspace root same npm command pnpm update --recursive --latest @socketsecurity/socket-patch (the dependency may be declared by any member)
vlt / vlx project label "npm" label "vlt" (hints unchanged)
npm, yarn global, version-manager prefixes unchanged unchanged

Root cause

update/channel.rs has no pnpm case: is_global_npm_install treats a pnpm global store as an npm global, upgrade_hint_for special-cases vlt/vlx only, and channel_label reports "npm" for every node_modules install.

Changes

  • update/channel.rs: a private NodeManager classifier (npm / pnpm / vlt / vlx). pnpm is recognized by a .pnpm virtual-store component in the canonical binary path (every isolated-linker install, global or project, including a custom PNPM_HOME), a pnpm home above a global store, or pnpm-lock.yaml beside the outermost node_modules (node-linker=hoisted). upgrade_hint_for routes through it; new channel_label_for(channel, path) names the manager, and commands/update.rs uses it for both the refusal and the --force override warning.
  • CLI_CONTRACT.md: the npm-family row of the managed-install table documents the pnpm commands and the per-manager label.

Tests (red → green)

  • Core unit (red on main: wrong hint / label, now green): update::channel::tests::pnpm_global_installs_get_pnpm_add_g (pnpm 9/10 macOS, pnpm 12 global/v11/<hash>, custom PNPM_HOME, yarn global stays npm), pnpm_project_installs_get_pnpm_add (isolated, hoisted + pnpm-lock.yaml, workspace root), labels_name_the_owning_node_manager. The existing global-store table drops its pnpm row, which was the defect.
  • CLI e2e on the spawned binary: self_update_channels_e2e::pnpm_project_refuses_with_pnpm_hint (human) and pnpm_global_refuses_with_pnpm_hint (--json, error.code: managed_install).
  • Manually checked with pnpm 11.27: pnpm update --recursive --latest <pkg> at a workspace root updates a member's dependency.

Commands run

  • cargo test -p socket-patch-core --lib update:: (86 passed)
  • cargo test -p socket-patch-cli --test update --test self_update_e2e --test self_update_failures_e2e and --lib update (all green)
  • cargo clippy --workspace --all-features -- -D warnings: clean
  • cargo fmt --all -- --check: only a pre-existing diff in patch/redirect/upstream/mod.rs (untouched here)

🤖 Generated with Claude Code


Note

Low Risk
Behavior change is limited to refusal messages and upgrade hints for managed installs; no download/swap or auth paths are touched.

Overview
pnpm-managed installs now get pnpm-specific upgrade guidance when --update refuses (or warns on --force) instead of npm commands that break pnpm layouts.

socket-patch-core adds path-based npm-family detection (NodeManager: npm / pnpm / vlt / vlx) using .pnpm paths, pnpm global store layout, pnpm-lock.yaml, and existing vlt/vlx signals. upgrade_hint_for returns pnpm add, pnpm add -g, or pnpm update --recursive --latest as appropriate; channel_label_for drives refusal text like “managed by pnpm” (vlt/vlx labeled correctly too). The CLI update command wires those into managed-install errors and override warnings; CLI_CONTRACT.md documents the expanded npm-family row.

Unit and e2e tests cover pnpm global/project/workspace paths and assert npm hints are not shown for pnpm installs.

Reviewed by Cursor Bugbot for commit 714722a. Configure here.


Generated by Claude Code

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
socket-patch --update and the update notice treated every node_modules
install as npm. A pnpm global install was told to run npm update -g,
which never sees pnpm's store, and a pnpm project was told to run
npm install, which writes a stray package-lock.json and breaks the
next pnpm install --frozen-lockfile.

pnpm installs are now recognized by the .pnpm virtual store in the
binary's path, a pnpm home above a global store, or pnpm-lock.yaml
beside node_modules. They are labelled "managed by pnpm" and given
pnpm add -g ...@latest (global), pnpm add ...@latest (project) or
pnpm update --recursive --latest ... (workspace root). vlt installs
are now labelled vlt.

Fixes #1111

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@mikolalysenko
Mikola Lysenko (mikolalysenko) marked this pull request as ready for review October 9, 2026 17:47
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

BugBot review

@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

bugbot run


Generated by Claude Code

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 714722a. Configure here.

@mikolalysenko
Mikola Lysenko (mikolalysenko) added this pull request to the merge queue Oct 9, 2026
Merged via the queue into main with commit 8ad90d4 Oct 9, 2026
53 checks passed
@mikolalysenko
Mikola Lysenko (mikolalysenko) deleted the agent/v5-update-pnpm-channel branch October 9, 2026 22:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants