Files
InvoiceShelf/pnpm-workspace.yaml
Darko Gjorgjijoski e48212b18a build: migrate frontend tooling to pnpm (v3) (#678)
* build: migrate frontend tooling to pnpm (v3)

Rebuilds the stale #673 on current 3.x so it doesn't revert #657's test
split, the Node-24 action bumps, or composer-install@4.0.0.

- package.json: packageManager pnpm@11.6.0; drop dead 'resolutions'
- pnpm-workspace.yaml: nodeLinker hoisted, allowBuilds vue-demi,
  overrides brace-expansion (replaces resolutions)
- pnpm-lock.yaml generated via 'pnpm import' from yarn.lock (keeps the
  resolved versions, incl. vite 8.0.3 / rolldown rc.12); yarn.lock removed
- docker.yaml + release.yaml: pnpm/action-setup@v6 + cache pnpm + pnpm
  install/build (action versions and the #657 split left intact; check.yaml
  needs no change — its test job is PHP-only after #657)
- 3 Dockerfiles: node:24 + corepack + pnpm install --frozen-lockfile && pnpm build
- Makefile, composer 'dev' script, CLAUDE.md, .gitignore -> pnpm

* fix(deps): pin vite to 8.0.5 (security)

Now that 3.x is the default branch, Dependabot flags vite <8.0.5. Pin to
8.0.5 (the patched version), which keeps rolldown 1.0.0-rc.12 — still
below 8.0.15 where the broken rolldown 1.0.3 (the init_runtime_dom_esm_bundler
chunk regression) starts, so the build stays clean. Mirrors v2's #674.
2026-06-12 14:04:16 +02:00

14 lines
570 B
YAML

# Flat, hoisted node_modules (npm/yarn-like) so the migration is a drop-in and
# transitive packages imported directly (e.g. flatpickr via vue-flatpickr-component)
# keep resolving. pnpm 11 reads these here, not from .npmrc.
nodeLinker: hoisted
# Build-script allow-listing (replaces package.json "pnpm.onlyBuiltDependencies").
# vue-demi needs its postinstall to select the Vue 3 entry; it is a trusted Vue-core shim.
allowBuilds:
vue-demi: true
# Replaces the dead package.json "resolutions" field (npm/pnpm read "overrides").
overrides:
brace-expansion: ^5.0.6