Repository navigation
build: migrate JavaScript tooling to pnpm 11 - #1792
Merged
Merged
Conversation
eitsupi
marked this pull request as draft
September 28, 2026 14:17
eitsupi
marked this pull request as ready for review
September 28, 2026 14:22
# Conflicts: # package-lock.json # package.json
eitsupi
requested review from
ManuelHentschel
and
a balanced review from Copilot
October 2, 2026 12:37
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The migration is consistent across configuration, development tasks, CI, packaging, and release workflows with no unresolved correctness issues.
Review effort: Balanced
Findings: None
What changed in this PR
Migrates JavaScript tooling from npm to pinned pnpm 11 with reproducible installs and safer extension packaging.
Changes:
- Replaces npm lock/install workflows with pnpm and frozen lockfiles.
- Uses declared local release tools and explicit dependency-build permissions.
- Updates packaging exclusions, VS Code tasks, and contributor documentation.
| File | Description |
|---|---|
package-lock.json |
Removes the npm lockfile. |
pnpm-lock.yaml |
Adds pnpm’s dependency lockfile. |
pnpm-workspace.yaml |
Controls dependency build-script permissions. |
package.json |
Pins pnpm and declares local tooling. |
tsconfig.json |
Restricts compilation to source TypeScript. |
.vscodeignore |
Defines an allowlist for VSIX contents. |
.vscode/tasks.json |
Migrates tasks to pnpm. |
.vscode/launch.json |
References the renamed pnpm-backed tasks. |
.github/workflows/main.yml |
Migrates CI installation and commands. |
.github/workflows/pre-release.yml |
Migrates pre-release packaging. |
.github/workflows/release.yml |
Uses reproducible installs and local publishing tools. |
CONTRIBUTING.md |
Updates contributor commands for pnpm. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
ManuelHentschel
approved these changes
Oct 2, 2026
ManuelHentschel
left a comment
Member
There was a problem hiding this comment.
I did a quick check on my local machine and the build seems to work fine.
Member
Author
|
Thanks! |
2 of 5 tasks
renkun-ken
added a commit
that referenced
this pull request
Oct 4, 2026
Match the package scripts and exact pnpm pin introduced by #1792. Document pnpm installation and use frozen installs and project-local commands throughout the Interactive validation guide.
renkun-ken
added a commit
that referenced
this pull request
Oct 4, 2026
* Add persistent multi-session R Interactive with rich output Implement independent plain R and arf agents, durable replay, native console control, session-bound language services, rich renderers, and notebook export. Include macOS storage and virtual-cell lint cache fixes with regression coverage. * Improve Interactive session controls, history, and output reliability * Document Positron workflow comparison and Interactive validation matrix * Fix output updates for queued Interactive cells * Compress and reclaim persistent Interactive plot snapshots * Open the Interactive session picker from the Command Palette * Hide stale Interactive sessions and clarify attached session status * Use compact Interactive toolbars and an accessible plot save menu * Expose session controls in the native Interactive toolbar * Format inline numeric tables with R print options * Improve Interactive export, lifecycle notices, and execution target selection * Preserve R Interactive sessions and views across reload and restart * Refresh Interactive kernel status and simplify session chooser * Fix Interactive widgets, history exports and virtual-cell diagnostics * Trim Interactive error traces and document live validation * Fix Interactive cell actions, error messages and new-session focus * Keep Workspace viewer aligned with Interactive session focus * Clarify Interactive connection status and add bulk session stopping * Show Interactive session ages and improve input language features * Handle optional arf availability before creating or restarting Interactive sessions * Simplify Interactive provider picker labels and show executable paths * Make Workspace dialog tests portable and retain CI failure logs * Fix Remote SSH Interactive startup and temporary-session diagnostics * Preserve titles and axes across Interactive plot panels * Preserve Interactive R libraries and correct plot rendering * Record public example and fallback validation results * Load processx runtime dependency in isolated renv sessions * Page Interactive plots and retain switchable R table printouts * Capture printed table snapshots with portable line endings * Support persistent Interactive sessions without tmux * Preserve research results and correct fallback plot pagination * Bound Interactive table snapshots and avoid full dataset copies * Add on-demand browsing and query controls to inline tables * Remove the inline table Columns panel * Fall back to compatible R-universe sess packages when source installation fails * Make binary installer fixtures portable across hosts and versions * Use repository archive names for Linux installer fixtures * Protect Interactive replay and native console connections Deliver replayed events before buffered live output, reject oversized rich events before IPC framing, and keep forked R workers off the parent console socket. Add regressions for all three failures. * Allow cancelling slow Interactive inspection requests Send interrupts even when no submitted cell is running, and return an interrupted RPC response without unwinding the R polling loop. Cover cancellation before and after the inspection timeout, followed by successful execution and inspection. * Fix Interactive output regressions found in public R examples * fix: bind Interactive language servers to their owning sessions * Refactor Interactive runtimes behind a session backend Separate execution policy and persistence from sess/arf transports, graphics, process lifecycle and runtime preparation. Preserve legacy configs and keep agent bundles independent of the sess cache. Fix inherited drafts in fresh native windows, stale saved URI ownership, and inconsistent observer execution errors. Cover early Stop, adopted frontend disposal, ambiguous dispatch and late process-exit events. * Fix Windows CI for Unix-only Interactive backend tests Keep backend configuration checks platform-independent and restrict socket-based agent contract tests to supported hosts. * Allow build and test scripts to run without pnpm on PATH Invoke local build tools directly while retaining pnpm dependency installation and CI. Document the pinned pnpm setup and npm script compatibility. * Restore pnpm workflow and align Interactive development instructions Match the package scripts and exact pnpm pin introduced by #1792. Document pnpm installation and use frozen installs and project-local commands throughout the Interactive validation guide. * Keep Interactive host settings local and clarify arf adoption Exclude host paths, runtime choices, and resource budgets from Settings Sync by default. Describe existing arf adoption independently of the terminal or session manager that launched it. * Use VS Code runtime and keep Interactive entry points private Remove the Node path setting, scope Electron Node mode to agent launches, and mark Interactive settings experimental. Verify private sess calls and full editor quit/reconnect across versions. * Keep native platform in Interactive process tests * Use consistent namespace syntax for sess internals * Configure interactive retention limits in MiB * Restore optional Node runtime override for Interactive * Fix Node override checks for tmux session launches * Move Interactive user documentation to the wiki
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of #1732.
I used https://github.com/oxc-project/oxc-vscode as a reference.
Why
Before updating the dependency backlog, we need a safer baseline for installing and running JavaScript tools. pnpm 11 denies dependency build scripts unless they are explicitly reviewed, applies a default cooldown to newly published packages, and exposes undeclared dependency assumptions through its isolated node_modules layout. This PR keeps those protections enabled.
The value here is combining an exact package-manager pin, pnpm's installation safeguards, and project-declared CLI tools. Release jobs should not fetch executables through npx at execution time.
Changes
@vscode/vsceandovsxas devDependencies; use project-local binaries for them andgit-cliff.esbuild's dependency build script, which prepares its platform-specific binary. Explicitly deny vsce-sign and keytar because these workflows do not sign VSIX files or use vsce's credential store.vsce --no-dependencies, and include only required files in the VSIX.Verification
A clean checkout completed
pnpm install --frozen-lockfileandpnpm run compilewithout changing tracked files. TypeScript pretest and VSIX packaging passed with Node 24. ESLint passed with 48 existing warnings and no errors. The VSIX contains no node_modules, source maps, or development files.