Skip to content

[WIP] Fix outdated lockfile for pnpm install - #11

Merged
insane66613 merged 1 commit into
mainfrom
copilot/update-pnpm-lockfile
Mar 12, 2026
Merged

[WIP] Fix outdated lockfile for pnpm install#11
insane66613 merged 1 commit into
mainfrom
copilot/update-pnpm-lockfile

Conversation

Copilot AI commented Mar 12, 2026

Copy link
Copy Markdown
  • Run pnpm install --no-frozen-lockfile to regenerate the lockfile
  • Commit the updated pnpm-lock.yaml
Original prompt

Repository: insane66613/MCP-SuperAssistant

A GitHub Actions job is failing in workflow .github/workflows/release.yml ("Release Extension") for run 23028763074, job 66882660384.

Failure occurs at the "Install dependencies" step running pnpm install.

Error:

  • ERR_PNPM_OUTDATED_LOCKFILE Cannot install with "frozen-lockfile" because pnpm-lock.yaml is not up to date with <ROOT>/pages/content/package.json
  • Mismatch in dependency specifiers:
    • In pages/content/package.json, autoprefixer is ^10.6.40
    • In pnpm-lock.yaml (importer pages/content), autoprefixer specifier is ^10.4.20

Task:

  1. Update the repository so that pnpm-lock.yaml is consistent with pages/content/package.json and CI pnpm install succeeds in frozen-lockfile mode.
  2. Prefer keeping frozen lockfile behavior (do NOT switch CI to --no-frozen-lockfile unless absolutely necessary).
  3. Implement the fix by updating the lockfile (and any other files pnpm updates) as needed.
  4. Ensure the Release workflow still uses pnpm 9.15.1 and Node 22.12.0 as currently configured.
  5. Create a pull request targeting main with a concise title like "Fix outdated pnpm lockfile".

Relevant references:

The following is the prior conversation context from the user's chat exploration (may be truncated):

User: Please find a solution for this failing job. Use the logs, job definition, and any referenced files where the failure occurred. Keep your response focused on the solution and include code suggestions when appropriate.

Assistant: The failure is happening in the “Install dependencies” step of the Release Extension workflow (.github/workflows/release.yml @ 54e10ace66fc88be4171d8a217136acae2492e1a, step runs pnpm install). The log snippet shows pnpm aborting because the lockfile doesn’t match the current workspace/package specifiers:

“Failure reason: specifiers in the lockfile ({ "@extension/env": "workspace:*", … "@radix-ui/react-dialog": "^1.1.6", … ajv … }) …”
This is the typical pnpm install --frozen-lockfile-style failure (CI treats installs as frozen by default in many setups / pnpm versions).

Fix (recommended): regenerate + commit pnpm-lock.yaml

  1. On your machine (or in a dedicated “lockfile update” PR), run:
    corepack enable
    corepack prepare pnpm@9.15.1 --activate
    pnpm install --no-frozen-lockfile
  2. Commit the updated pnpm-lock.yaml and push.

This resolves the root cause: the workflow is using pnpm 9.15.1 (see .github/workflows/release.yml and package.json#packageManager), but the lockfile currently does not align with what pnpm computes from your workspace importers (note the workspace importers like chrome-extension, pages/content, etc. in pnpm-lock.yaml).

Fix (CI-side workaround): explicitly allow lockfile updates in Release workflow

If you don’t want releases to be blocked by a lockfile mismatch (not ideal for reproducibility), change the install step in .github/workflows/release.yml from:

- name: Install dependencies
  run: pnpm install

to:

- name: Install dependencies
  run: pnpm install --no-frozen-lockfile

This matches the error message guidance in the log (“use pnpm install --no-frozen-lockfile”).

Why this is likely happening in your repo

  • You have a pnpm workspace (pnpm-workspace.yaml) including chrome-extension, pages/*, and packages/*.
  • The lockfile shows many workspace “importers” and workspace:* specifiers (e.g., pages/content depends on @extension/env, @extension/shared, etc.).
  • Any change to any package.json in those workspaces (dependency versions, adding/removing deps, moving packages in/out of the workspace patterns) requires re-generating and committing the lockfile—or pnpm will refuse to proceed in CI.

Quick sanity check after applying the fix

After committing the regenerated lockfile (recommended path), the release job should proceed past pnpm install and then run:

  • pnpm build
  • pnpm zip (note: your zip script already runs pnpm build again, so you may optionally simplify later, but it’s not the current failure)

If you want, paste the full pnpm install error block (the log was truncated right after the “specifiers in the lockfile” list), and I can point to the exact workspace/package whose specifiers diverged.

User: Run pnpm install
Scope: all 15 workspace projects
 ERR_PNPM_OUTDATED_LOCKFILE  Cannot install with "frozen-lockfile" because pnpm-lock.yaml is not up to date with /pages/content/package.json

Note that in CI environments this setting is true by default. If you still need to run install in such cases, use "pnpm install --no-frozen-lockfile"

Failure reason:
specifiers in the lockfile ({"@extension/...

This pull request was created from Copilot chat.


💬 Send tasks to Copilot coding agent from Slack and Teams to turn conversations into code. Copilot posts an update in your thread when it's finished.

@insane66613
insane66613 marked this pull request as ready for review March 12, 2026 23:34
@insane66613
insane66613 merged commit 43dccfe into main Mar 12, 2026
1 of 2 checks passed
Copilot AI requested a review from insane66613 March 12, 2026 23:34
Copilot stopped work on behalf of insane66613 due to an error March 12, 2026 23:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants