Repository navigation
Give pnpm installs pnpm upgrade commands (#1111) - #1350
Merged
Mikola Lysenko (mikolalysenko) merged 4 commits intoOct 9, 2026
Merged
Conversation
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
socket-patch --update and the update notice treated every node_modules install as npm. A pnpm global install was told to run npm update -g, which never sees pnpm's store, and a pnpm project was told to run npm install, which writes a stray package-lock.json and breaks the next pnpm install --frozen-lockfile. pnpm installs are now recognized by the .pnpm virtual store in the binary's path, a pnpm home above a global store, or pnpm-lock.yaml beside node_modules. They are labelled "managed by pnpm" and given pnpm add -g ...@latest (global), pnpm add ...@latest (project) or pnpm update --recursive --latest ... (workspace root). vlt installs are now labelled vlt. Fixes #1111 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Mikola Lysenko (mikolalysenko)
marked this pull request as ready for review
October 9, 2026 17:47
Collaborator
Author
|
BugBot review |
Mikola Lysenko (mikolalysenko)
enabled auto-merge
October 9, 2026 17:47
Tanmay Singla (Tanmay182003)
approved these changes
Oct 9, 2026
Collaborator
Author
|
bugbot run Generated by Claude Code |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 714722a. Configure here.
Mikola Lysenko (mikolalysenko)
disabled auto-merge
October 9, 2026 20:41
Mikola Lysenko (mikolalysenko)
enabled auto-merge
October 9, 2026 21:32
Mikola Lysenko (mikolalysenko)
deleted the
agent/v5-update-pnpm-channel
branch
October 9, 2026 22:13
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
LLM Description written by Claude Code:claude-opus-5-5
Fixes #1111
Summary
socket-patch --update(and the passive update notice, which shares the same hint) now tells a pnpm install to upgrade through pnpm and labels the refusal "managed by pnpm".npm update -g @socketsecurity/socket-patch(a no-op: npm never sees pnpm's store)pnpm add -g @socketsecurity/socket-patch@latestnpm install @socketsecurity/socket-patch@latest(writes a straypackage-lock.json; nextpnpm install --frozen-lockfilefails)pnpm add @socketsecurity/socket-patch@latestpnpm update --recursive --latest @socketsecurity/socket-patch(the dependency may be declared by any member)Root cause
update/channel.rshas no pnpm case:is_global_npm_installtreats a pnpmglobalstore as an npm global,upgrade_hint_forspecial-cases vlt/vlx only, andchannel_labelreports "npm" for everynode_modulesinstall.Changes
update/channel.rs: a privateNodeManagerclassifier (npm / pnpm / vlt / vlx). pnpm is recognized by a.pnpmvirtual-store component in the canonical binary path (every isolated-linker install, global or project, including a customPNPM_HOME), apnpmhome above aglobalstore, orpnpm-lock.yamlbeside the outermostnode_modules(node-linker=hoisted).upgrade_hint_forroutes through it; newchannel_label_for(channel, path)names the manager, andcommands/update.rsuses it for both the refusal and the--forceoverride warning.CLI_CONTRACT.md: the npm-family row of the managed-install table documents the pnpm commands and the per-manager label.Tests (red → green)
update::channel::tests::pnpm_global_installs_get_pnpm_add_g(pnpm 9/10 macOS, pnpm 12global/v11/<hash>, custom PNPM_HOME, yarn global stays npm),pnpm_project_installs_get_pnpm_add(isolated, hoisted +pnpm-lock.yaml, workspace root),labels_name_the_owning_node_manager. The existing global-store table drops its pnpm row, which was the defect.self_update_channels_e2e::pnpm_project_refuses_with_pnpm_hint(human) andpnpm_global_refuses_with_pnpm_hint(--json,error.code: managed_install).pnpm update --recursive --latest <pkg>at a workspace root updates a member's dependency.Commands run
cargo test -p socket-patch-core --lib update::(86 passed)cargo test -p socket-patch-cli --test update --test self_update_e2e --test self_update_failures_e2eand--lib update(all green)cargo clippy --workspace --all-features -- -D warnings: cleancargo fmt --all -- --check: only a pre-existing diff inpatch/redirect/upstream/mod.rs(untouched here)🤖 Generated with Claude Code
Note
Low Risk
Behavior change is limited to refusal messages and upgrade hints for managed installs; no download/swap or auth paths are touched.
Overview
pnpm-managed installs now get pnpm-specific upgrade guidance when
--updaterefuses (or warns on--force) instead of npm commands that break pnpm layouts.socket-patch-coreadds path-based npm-family detection (NodeManager: npm / pnpm / vlt / vlx) using.pnpmpaths, pnpm global store layout,pnpm-lock.yaml, and existing vlt/vlx signals.upgrade_hint_forreturnspnpm add,pnpm add -g, orpnpm update --recursive --latestas appropriate;channel_label_fordrives refusal text like “managed by pnpm” (vlt/vlx labeled correctly too). The CLIupdatecommand wires those into managed-install errors and override warnings;CLI_CONTRACT.mddocuments the expanded npm-family row.Unit and e2e tests cover pnpm global/project/workspace paths and assert npm hints are not shown for pnpm installs.
Reviewed by Cursor Bugbot for commit 714722a. Configure here.
Generated by Claude Code