mirror of
https://github.com/NixOS/nixpkgs.git
synced 2026-10-03 13:30:36 +00:00
pnpm_10_latest: init at 10.34.5
Keep pnpm_10 at 10.34.0 for out-of-tree compatibility and mark it insecure. Add pnpm_10_latest at 10.34.5 and make variant generation and updater targets attribute-specific. Not-cherry-picked-because: release-26.05 has different pnpm variants and lockfiles Assisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)
This commit is contained in:
@@ -306,6 +306,7 @@ This package puts the corepack wrappers for pnpm and yarn in your PATH, and they
|
||||
### pnpm {#javascript-pnpm}
|
||||
|
||||
pnpm is available as the top-level package `pnpm`. Additionally, there are variants pinned to certain major versions, like `pnpm_8`, `pnpm_9`, `pnpm_10`, `pnpm_10_29_2` and `pnpm_11`, which support different sets of lock file versions.
|
||||
`pnpm_10_latest` tracks the latest pnpm 10 release, while `pnpm_10` remains fixed for compatibility.
|
||||
|
||||
When packaging an application that includes a `pnpm-lock.yaml`, you need to fetch the pnpm store for that project using a fixed-output-derivation. The function `fetchPnpmDeps` can create this pnpm store derivation. In conjunction, the setup hook `pnpmConfigHook` will prepare the build environment to install the pre-fetched dependencies store. Here is an example for a package that contains `package.json` and a `pnpm-lock.yaml` files using the fetcher and setup hook above:
|
||||
|
||||
|
||||
@@ -17,6 +17,11 @@ let
|
||||
"CVE-2026-50017"
|
||||
"CVE-2026-50573"
|
||||
"CVE-2026-55699"
|
||||
"CVE-2026-59194"
|
||||
"CVE-2026-59195"
|
||||
"CVE-2026-59196"
|
||||
"CVE-2026-82392"
|
||||
"CVE-2026-82393"
|
||||
];
|
||||
};
|
||||
"9" = {
|
||||
@@ -30,6 +35,11 @@ let
|
||||
"CVE-2026-50017"
|
||||
"CVE-2026-50573"
|
||||
"CVE-2026-55699"
|
||||
"CVE-2026-59194"
|
||||
"CVE-2026-59195"
|
||||
"CVE-2026-59196"
|
||||
"CVE-2026-82392"
|
||||
"CVE-2026-82393"
|
||||
];
|
||||
};
|
||||
# 10.29.3 made a breaking change: https://github.com/pnpm/pnpm/issues/10601.
|
||||
@@ -38,6 +48,7 @@ let
|
||||
"10_29_2" = {
|
||||
version = "10.29.2";
|
||||
hash = "sha256-hAL2daH0zJ1PJ7v6s1wtSi4dfrATHfA9rQlhnoZnTQw=";
|
||||
enableUpdateScript = false;
|
||||
knownVulnerabilities = [
|
||||
"CVE-2026-48995"
|
||||
"CVE-2026-50014"
|
||||
@@ -46,11 +57,34 @@ let
|
||||
"CVE-2026-50017"
|
||||
"CVE-2026-50573"
|
||||
"CVE-2026-55699"
|
||||
"CVE-2026-59194"
|
||||
"CVE-2026-59195"
|
||||
"CVE-2026-59196"
|
||||
"CVE-2026-82392"
|
||||
"CVE-2026-82393"
|
||||
];
|
||||
};
|
||||
# 10.34.1 tightened remote tarball integrity checks, which can break existing lockfiles.
|
||||
# Keep the compatibility variant at 10.34.0 for out-of-tree consumers.
|
||||
"10" = {
|
||||
version = "10.34.0";
|
||||
hash = "sha256-WOFDJYhx31FYm2UcBiBdq+xIdmpdu6PCWZm2m1C+WY4=";
|
||||
enableUpdateScript = false;
|
||||
knownVulnerabilities = [
|
||||
"CVE-2026-55487"
|
||||
"CVE-2026-55698"
|
||||
"CVE-2026-55180"
|
||||
"CVE-2026-55697"
|
||||
"CVE-2026-59194"
|
||||
"CVE-2026-59195"
|
||||
"CVE-2026-59196"
|
||||
"CVE-2026-82392"
|
||||
"CVE-2026-82393"
|
||||
];
|
||||
};
|
||||
"10_latest" = {
|
||||
version = "10.34.5";
|
||||
hash = "sha256-zLXEecqxsAYhMlv+fUyaioAx56Ul1ySeJ17L7IGwjbI=";
|
||||
};
|
||||
"11" = {
|
||||
version = "11.27.0";
|
||||
@@ -64,10 +98,11 @@ let
|
||||
};
|
||||
|
||||
callPnpmNode =
|
||||
variant:
|
||||
packageAttrName: variant:
|
||||
callPackage ./generic.nix (
|
||||
variant
|
||||
// {
|
||||
inherit packageAttrName;
|
||||
#FIXME: remove this hack in a future version.
|
||||
nodejs = null; # Passing null to detect out-of-tree overrides
|
||||
}
|
||||
@@ -75,8 +110,15 @@ let
|
||||
|
||||
callPnpmRust = callPackage ./generic-rust.nix;
|
||||
|
||||
callPnpm = variant: if variant ? cargoHash then callPnpmRust variant else callPnpmNode variant;
|
||||
callPnpm =
|
||||
packageAttrName: variant:
|
||||
if variant ? cargoHash then callPnpmRust variant else callPnpmNode packageAttrName variant;
|
||||
|
||||
mkPnpm = versionSuffix: variant: nameValuePair "pnpm_${versionSuffix}" (callPnpm variant);
|
||||
mkPnpm =
|
||||
versionSuffix: variant:
|
||||
let
|
||||
packageAttrName = "pnpm_${versionSuffix}";
|
||||
in
|
||||
nameValuePair packageAttrName (callPnpm packageAttrName variant);
|
||||
in
|
||||
mapAttrs' mkPnpm variants
|
||||
|
||||
@@ -15,6 +15,8 @@
|
||||
tests,
|
||||
|
||||
withNode ? true,
|
||||
enableUpdateScript ? true,
|
||||
packageAttrName ? "pnpm_${lib.versions.major version}",
|
||||
version,
|
||||
hash,
|
||||
knownVulnerabilities ? [ ],
|
||||
@@ -95,7 +97,7 @@ stdenvNoCC.mkDerivation (finalAttrs: {
|
||||
|
||||
passthru =
|
||||
let
|
||||
pnpm' = buildPackages."pnpm_${lib.versions.major version}";
|
||||
pnpm' = buildPackages.${packageAttrName};
|
||||
in
|
||||
{
|
||||
fetchDeps =
|
||||
@@ -129,6 +131,8 @@ stdenvNoCC.mkDerivation (finalAttrs: {
|
||||
inherit (tests) pnpm;
|
||||
version = lib.optionalAttrs withNode (testers.testVersion { package = finalAttrs.finalPackage; });
|
||||
};
|
||||
}
|
||||
// lib.optionalAttrs enableUpdateScript {
|
||||
updateScript = writeScript "pnpm-update-script" ''
|
||||
#!/usr/bin/env nix-shell
|
||||
#!nix-shell -i bash -p curl jq common-updater-scripts
|
||||
@@ -152,7 +156,7 @@ stdenvNoCC.mkDerivation (finalAttrs: {
|
||||
|
||||
latestVersion="''${latestTag#v}"
|
||||
|
||||
update-source-version pnpm_${majorVersion} "$latestVersion" --file=./pkgs/development/tools/pnpm/default.nix
|
||||
update-source-version ${packageAttrName} "$latestVersion" --file=./pkgs/development/tools/pnpm/default.nix
|
||||
'';
|
||||
};
|
||||
|
||||
|
||||
@@ -2960,6 +2960,7 @@ with pkgs;
|
||||
pnpm_9
|
||||
pnpm_10_29_2
|
||||
pnpm_10
|
||||
pnpm_10_latest
|
||||
pnpm_11
|
||||
pnpm_12
|
||||
;
|
||||
|
||||
Reference in New Issue
Block a user